{"schema_version":"1.7.3","id":"GO-2025-3702","published":"2025-05-23T15:18:56Z","modified":"2026-03-03T04:56:37.683242Z","aliases":["CVE-2025-48069","GHSA-2c47-m757-32g6"],"summary":"Insufficient input sanitization in ejson2env in github.com/Shopify/ejson2env","details":"Insufficient input sanitization in ejson2env in github.com/Shopify/ejson2env","affected":[{"package":{"name":"github.com/Shopify/ejson2env","ecosystem":"Go","purl":"pkg:golang/github.com/Shopify/ejson2env"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2025-3702.json"}},{"package":{"name":"github.com/Shopify/ejson2env/v2","ecosystem":"Go","purl":"pkg:golang/github.com/Shopify/ejson2env/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.0.8"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2025-3702.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/Shopify/ejson2env/security/advisories/GHSA-2c47-m757-32g6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48069"},{"type":"FIX","url":"https://github.com/Shopify/ejson2env/commit/592b3ceea967fee8b064e70983e8cec087b6d840"}],"database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2025-3702"}}