Goploy Package Vulnerability: Cross-namespace IDOR and RCE Risk
An early warning has been issued regarding a potential vulnerability in the Goploy package that could allow unauthorized users to perform cross-namespace IDOR attacks and achieve remote code execution. Users of the `zhenorzz/goploy` package are advised to take precautions.
What happened
Reportedly, the Goploy package contains a vulnerability due to a lack of namespace checks, which may allow unauthorized users to read, write, or delete files across any project within the installation. This vulnerability appears to enable remote code execution if a compromised git remote URL is used. The issue is currently under investigation with the tracked ID GHSA-26RH-24RG-J3VV.
To assess your exposure, check if your project utilizes the `zhenorzz/goploy` package. If so, it is recommended to avoid using the package until a patch is released. For those currently using it, ensure that only trusted users have access to the `manager` role or `FileSync` / `EditProject` permissions to mitigate potential risks.
For more detailed information, consult the primary source at [GHSA-26rh-24rg-j3vv](https://github.com/zhenorzz/goploy/security/advisories/GHSA-26rh-24rg-j3vv). The severity of this issue is high, and further updates will be provided as more information becomes available.
How 0Day mitigates this
zhenorzz/goploy is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.