CARGO · JULY 2026 · EARLY WARNING

skilo cargo Package Vulnerability: Arbitrary Local File Disclosure

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-6XX4-9WP6-65P7Severity: HIGH

An early warning has been issued regarding a vulnerability in the skilo cargo package where the 'add' command mishandles symbolic links, potentially allowing a malicious skill source to disclose arbitrary local files.

What happened

The skilo cargo package's 'add' command is reportedly mishandling symbolic links, which could allow a malicious skill source to read arbitrary local files and place their contents inside the installed skill directory. This vulnerability, tracked under GHSA-6XX4-9WP6-65P7, affects skilo versions prior to 0.11.1. It is under investigation and has been classified as a critical CVE. Professional software engineers using skilo should upgrade to version 0.11.1 or later to mitigate this risk. Additionally, it is recommended to avoid installing skills from untrusted sources and to inspect skill sources for symbolic links before using the'skilo add' command.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If skilo is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats