{"id":"GHSA-vjgj-42f6-7997","aliases":["GO-2026-5664"],"url":"https://o3.security/vulnerability/GHSA-vjgj-42f6-7997","summary":"netfoil's optional seccomp sandboxing was not applied","details":"### Summary\nThe optional flag `--filter-system-calls` was not applied even if specified.\n\n### Details\nThis is a defense in depth feature to apply additional seccomp filters after the binary has started. The example config also sandboxes the binary with systemd.\n\n### Impact\nReduced sandboxing of the netfoil binary.","published":"2026-04-29T22:23:41Z","modified":"2026-06-25T23:11:47.415769012Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/tinfoil-factory/netfoil","fixedVersion":"0.2.1"}],"fix":{"url":"https://github.com/tinfoil-factory/netfoil/commit/8c84f1b03adf1df5b4e6d07a49043d13dbbf9ee1","label":"tinfoil-factory/netfoil@8c84f1b"},"references":[{"type":"WEB","url":"https://github.com/tinfoil-factory/netfoil/security/advisories/GHSA-vjgj-42f6-7997"},{"type":"WEB","url":"https://github.com/tinfoil-factory/netfoil/commit/8c84f1b03adf1df5b4e6d07a49043d13dbbf9ee1"},{"type":"PACKAGE","url":"https://github.com/tinfoil-factory/netfoil"},{"type":"WEB","url":"https://github.com/tinfoil-factory/netfoil/releases/tag/v0.2.1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-06-25T23:11:47.415769012Z"}}