{"id":"GO-2025-3804","summary":"Juju zip slip vulnerability via authenticated endpoint in github.com/juju/juju","details":"Juju zip slip vulnerability via authenticated endpoint in github.com/juju/juju","aliases":["CVE-2025-53513","GHSA-24ch-w38v-xmh8"],"modified":"2026-03-03T04:57:21.799494Z","published":"2025-07-28T19:57:13Z","database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2025-3804"},"references":[{"type":"ADVISORY","url":"https://github.com/juju/juju/security/advisories/GHSA-24ch-w38v-xmh8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-53513"},{"type":"FIX","url":"https://github.com/juju/juju/commit/6356e984b82a4a7b9771ff5e51e297ad62f3b405"},{"type":"FIX","url":"https://github.com/juju/juju/commit/ff39557a137c0e95d4cd3553b0f19c859c6f5d8e"},{"type":"WEB","url":"https://drive.google.com/file/d/1pHRNiaA8LyMVJYwIyTqelsqJ9FmImDf0/view"},{"type":"WEB","url":"https://github.com/juju/juju/blob/3.6/apiserver/apiserver.go#L754"},{"type":"WEB","url":"https://github.com/juju/juju/blob/3.6/apiserver/apiserver.go#L897"},{"type":"WEB","url":"https://github.com/juju/juju/blob/3.6/apiserver/apiserver.go#L990"}],"affected":[{"package":{"name":"github.com/juju/juju","ecosystem":"Go","purl":"pkg:golang/github.com/juju/juju"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.0-20250619215741-6356e984b82a"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2025-3804.json"}}],"schema_version":"1.7.3"}