PT-2026-39434 · Go · Github.Com/Tinfoil-Factory/Netfoil

Published

2026-04-29

·

Updated

2026-04-29

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Summary

The optional flag --filter-system-calls was not applied even if specified.

Details

This is a defense in depth feature to apply additional seccomp filters after the binary has started. The example config also sandboxes the binary with systemd.

Impact

Reduced sandboxing of the netfoil binary.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-VJGJ-42F6-7997

Affected Products

Github.Com/Tinfoil-Factory/Netfoil