{"id":"GO-2026-4960","summary":"Neko has a Self-service Privilege Escalation for Authenticated Users in github.com/m1k1o/neko/server","details":"Neko has a Self-service Privilege Escalation for Authenticated Users in github.com/m1k1o/neko/server","aliases":["CVE-2026-39386","GHSA-2gw9-c2r2-f5qf"],"modified":"2026-06-01T22:00:20.498066990Z","published":"2026-06-01T21:35:18Z","database_specific":{"url":"https://pkg.go.dev/vuln/GO-2026-4960","review_status":"REVIEWED"},"references":[{"type":"ADVISORY","url":"https://github.com/m1k1o/neko/security/advisories/GHSA-2gw9-c2r2-f5qf"},{"type":"WEB","url":"https://github.com/m1k1o/neko/commit/6b561feb9016badea99ae7305091c0ff55e1d114"},{"type":"WEB","url":"https://github.com/m1k1o/neko/commit/c54bcf1ee211e28104a2bb6db59583a39c4a4d6e"},{"type":"WEB","url":"https://github.com/m1k1o/neko/releases/tag/v3.0.11"},{"type":"WEB","url":"https://github.com/m1k1o/neko/releases/tag/v3.1.2"}],"affected":[{"package":{"name":"github.com/m1k1o/neko/server","ecosystem":"Go","purl":"pkg:golang/github.com/m1k1o/neko/server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.0.0-20250326225119-51bbad7650d3"},{"fixed":"0.0.0-20260406184107-c54bcf1ee211"}]}],"ecosystem_specific":{"custom_ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.0.11"},{"introduced":"3.1.0"},{"fixed":"3.1.2"}]}],"imports":[{"symbols":["ApiManagerCtx.UpdateProfile"],"path":"github.com/m1k1o/neko/server/internal/api"}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-4960.json"}}],"schema_version":"1.7.5"}