mediumVulnerability

GHSA-vjgj-42f6-7997

### Summary The optional flag `--filter-system-calls` was not applied even if specified. ### Details This is a defense in depth feature to apply additional seccomp filters after the binary has started. The example config also sandboxes the binary with systemd. ### Impact Reduced sandboxing of the netfoil binary.

Properties

ghsa_id
GHSA-vjgj-42f6-7997
severity
medium
summary
netfoil's optional seccomp sandboxing was not applied
cve_id
GHSA-vjgj-42f6-7997
is_ghsa_only
true
ghsa_published
2026-04-29T22:23:41Z
source_url
https://github.com/advisories/GHSA-vjgj-42f6-7997
ghsa_updated
2026-04-29T22:23:42Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]go/github.com/tinfoil-factory/netfoil

AFFECTS (1)

[Software]go/github.com/tinfoil-factory/netfoil

HAS_WEAKNESS (1)

[Weakness]Incomplete Filtering of Special Elements

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph