{"schema_version":"1.7.3","id":"GO-2025-3456","published":"2025-02-07T22:47:45Z","modified":"2026-03-03T04:57:12.233117Z","aliases":["CVE-2025-24786","GHSA-9r4c-jwx3-3j76"],"summary":"WhoDB has a path traversal opening Sqlite3 database in github.com/clidey/whodb/core","details":"WhoDB has a path traversal opening Sqlite3 database in github.com/clidey/whodb/core","affected":[{"package":{"name":"github.com/clidey/whodb/core","ecosystem":"Go","purl":"pkg:golang/github.com/clidey/whodb/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.0-20250127172032-547336ac73c8"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2025-3456.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/clidey/whodb/security/advisories/GHSA-9r4c-jwx3-3j76"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-24786"},{"type":"WEB","url":"https://github.com/clidey/whodb/blob/ba6eb81d0ca40baead74bca58b2567166999d6a6/core/src/plugins/sqlite3/db.go#L14-L20"},{"type":"WEB","url":"https://github.com/clidey/whodb/blob/ba6eb81d0ca40baead74bca58b2567166999d6a6/core/src/plugins/sqlite3/db.go#L26"},{"type":"WEB","url":"https://github.com/clidey/whodb/commit/547336ac73c8d17929c18c3941c0d5b0099753cc"}],"database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2025-3456"}}