{"id":"GO-2026-5825","summary":"gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic","details":"gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic","aliases":["CVE-2026-49339","GHSA-2fp4-5v5c-4448"],"modified":"2026-07-07T16:00:21.468492496Z","published":"2026-07-07T15:26:32Z","database_specific":{"url":"https://pkg.go.dev/vuln/GO-2026-5825","review_status":"UNREVIEWED"},"references":[{"type":"ADVISORY","url":"https://github.com/sentriz/gonic/security/advisories/GHSA-2fp4-5v5c-4448"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49339"},{"type":"WEB","url":"https://github.com/sentriz/gonic/commit/0824bed88f6bbc490ba28bf09d28e5dfeb07b445"},{"type":"WEB","url":"https://github.com/sentriz/gonic/commit/6dd71e6"}],"affected":[{"package":{"name":"go.senan.xyz/gonic","ecosystem":"Go","purl":"pkg:golang/go.senan.xyz/gonic"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.21.0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-5825.json"}}],"schema_version":"1.7.5"}