Security: getsops/sops
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Switching user in `sops exec-file` and `sops exec-env` sets user's UID as GID (Unix only)GHSA-pvcx-747w-54qw published
Aug 14, 2026 by felixfonteinLow -
Memory exhaustion when decrypting untrusted INI or DotEnv filesGHSA-hqjv-fvgv-rh27 published
Aug 14, 2026 by felixfonteinModerate -
HC Vault / OpenBao token exfiltration when decrypting untrusted SOPS-encrypted filesGHSA-jgf3-f6rg-8x3h published
Aug 14, 2026 by felixfonteinHigh -
Path traversal in `sops exec-file --filename` leaks decrypted plaintext outside temporary directoryGHSA-x4cm-pcq4-39j4 published
Aug 14, 2026 by felixfonteinModerate -
Local directory executable lookup in sops (Windows-only)GHSA-x5c7-x7m2-rhmf published
Apr 22, 2021 by ajvbLow
Learn more about advisories related to getsops/sops in the GitHub Advisory Database