Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server in github.com/argoproj/argo-cd
{ "review_status": "UNREVIEWED", "url": "https://pkg.go.dev/vuln/GO-2022-0499" }