kelseyhightower / nocode

The best way to write secure and reliable applications. Write nothing; deploy nowhere.
Apache License 2.0
59.56k stars 4.72k forks source link

Zero day vulnerability #5232

Open Megagyger opened 2 months ago

Megagyger commented 2 months ago

Posting this as critical. I managed to exploit this vulnerability this morning

lukemt commented 2 months ago

This is concerning. Please tell no-one about it so that we can calm down again

mgrijalva commented 1 month ago

My company has a hard dependency on this project. Was just notified of this exploit today. I was able to reproduce it by doing the following:

Please fix. Thx

shandrew commented 1 month ago

Let's contribute helpfully to this open source project instead of putting more stress on the maintainer and letting some xz-situation happen. I will add: