Vulnerability GO-2026-6591
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
6 hours ago
October 01, 2026 at 08:23 PM UTC
ZITADEL: Actions V1 sandbox escape: host file read via require() in github.com/zitadel/zitadel
v0.0.0 - v1.80.0-v2.20
v0.0.0 - v1.80.0-v2.20
Summary
ZITADEL: Actions V1 sandbox escape: host file read via require() in github.com/zitadel/zitadel
Details
ZITADEL: Actions V1 sandbox escape: host file read via require() in github.com/zitadel/zitadel
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
6 hours ago
ZITADEL: MFA bypass via session reuse in Login V2 in github.com/zitadel/zitadel
v0.0.0 - v1.80.0-v2.20 GO-2026-6589
v0.0.0 - v1.80.0-v2.20 GO-2026-6589
High Risk
7 days ago
ZITADEL: MFA bypass via session reuse in Login V2
v0.0.0 - v1.80.0-v2.20 GHSA-9993-rfwp-rhwf
v0.0.0 - v1.80.0-v2.20 GHSA-9993-rfwp-rhwf
High Risk
7 days ago
ZITADEL: Actions V1 sandbox escape: host file read via require()
v0.0.0 - v1.80.0-v2.20 GHSA-fgmf-7rf8-m6vf
v0.0.0 - v1.80.0-v2.20 GHSA-fgmf-7rf8-m6vf
Unknown
15 days ago
ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider in github.com/zitadel/zitadel
v0.0.0 - v1.87.5 GO-2026-6469
v0.0.0 - v1.87.5 GO-2026-6469
Unknown
15 days ago
ZITADEL: Auto-linking by email: IdP-side email verification is not checked in github.com/zitadel/zitadel
v0.0.0 - v1.87.5 GO-2026-6470
v0.0.0 - v1.87.5 GO-2026-6470
Impacted packages
Timeline
Published
6 hours ago
October 01, 2026 at 08:23 PM UTC
Last Modified
6 hours ago
October 01, 2026 at 08:45 PM UTC