An attacker can craft a remote request to upload a file to "/group1/upload" that uses path traversal to instead write the file contents to an attacker controlled path on the server.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2023-1713" }