github.com/montferret/ferret
Declarative data automation language and Go runtime for structured extraction workflows.
Activity
- Latest release
- 6mo ago
- Total releases
- 20
- Cadence
- ~16 days
- Last 12 months
- 1
Reach
- Stars
- 6.0k
Details
- First release
- Apr 23, 2021
| Version | Released | |
|---|---|---|
v1.0.0
major
|
v1.0.0
major
Dependencies (18)
+ 10 more |
|
v0.18.1
patch
1 CVE
CVE-2026-34783
GHSA-j6v5-g24h-vg4j
GO-2026-5452
Apr 01, 2026
Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
8.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
High
SummaryA path traversal vulnerability in Ferret's ExploitationThe attacker hosts a malicious website. The victim is an operator running Ferret to scrape it. The operator writes a standard scraping query that saves scraped files using filenames from the website -- a completely normal and expected pattern. Attack Flow
Realistic Targets| Target Path | Impact |
|-------------|--------|
| Proof of ConceptFilesThree files are provided in the
Reproduction Steps
Observed Output
Suggested FixOption 1: Reject path traversal in
|
v0.18.1
patch
Dependencies (18)
+ 10 more |
|
v0.18.0
minor
1 CVE
CVE-2026-34783
GHSA-j6v5-g24h-vg4j
GO-2026-5452
Apr 01, 2026
Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
8.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
High
SummaryA path traversal vulnerability in Ferret's ExploitationThe attacker hosts a malicious website. The victim is an operator running Ferret to scrape it. The operator writes a standard scraping query that saves scraped files using filenames from the website -- a completely normal and expected pattern. Attack Flow
Realistic Targets| Target Path | Impact |
|-------------|--------|
| Proof of ConceptFilesThree files are provided in the
Reproduction Steps
Observed Output
Suggested FixOption 1: Reject path traversal in
|
v0.18.0
minor
Dependencies (18)
+ 10 more |
|
v0.17.0
minor
1 CVE
CVE-2026-34783
GHSA-j6v5-g24h-vg4j
GO-2026-5452
Apr 01, 2026
Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
8.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
High
SummaryA path traversal vulnerability in Ferret's ExploitationThe attacker hosts a malicious website. The victim is an operator running Ferret to scrape it. The operator writes a standard scraping query that saves scraped files using filenames from the website -- a completely normal and expected pattern. Attack Flow
Realistic Targets| Target Path | Impact |
|-------------|--------|
| Proof of ConceptFilesThree files are provided in the
Reproduction Steps
Observed Output
Suggested FixOption 1: Reject path traversal in
|
v0.17.0
minor
Dependencies (18)
+ 10 more |
|
v0.16.7
patch
1 CVE
CVE-2026-34783
GHSA-j6v5-g24h-vg4j
GO-2026-5452
Apr 01, 2026
Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
8.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
High
SummaryA path traversal vulnerability in Ferret's ExploitationThe attacker hosts a malicious website. The victim is an operator running Ferret to scrape it. The operator writes a standard scraping query that saves scraped files using filenames from the website -- a completely normal and expected pattern. Attack Flow
Realistic Targets| Target Path | Impact |
|-------------|--------|
| Proof of ConceptFilesThree files are provided in the
Reproduction Steps
Observed Output
Suggested FixOption 1: Reject path traversal in
|
v0.16.7
patch
Dependencies (18)
+ 10 more |
|
v0.16.6
patch
1 CVE
CVE-2026-34783
GHSA-j6v5-g24h-vg4j
GO-2026-5452
Apr 01, 2026
Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
8.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
High
SummaryA path traversal vulnerability in Ferret's ExploitationThe attacker hosts a malicious website. The victim is an operator running Ferret to scrape it. The operator writes a standard scraping query that saves scraped files using filenames from the website -- a completely normal and expected pattern. Attack Flow
Realistic Targets| Target Path | Impact |
|-------------|--------|
| Proof of ConceptFilesThree files are provided in the
Reproduction Steps
Observed Output
Suggested FixOption 1: Reject path traversal in
|
v0.16.6
patch
Dependencies (18)
+ 10 more |
|
v0.16.5
patch
1 CVE
CVE-2026-34783
GHSA-j6v5-g24h-vg4j
GO-2026-5452
Apr 01, 2026
Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
8.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
High
SummaryA path traversal vulnerability in Ferret's ExploitationThe attacker hosts a malicious website. The victim is an operator running Ferret to scrape it. The operator writes a standard scraping query that saves scraped files using filenames from the website -- a completely normal and expected pattern. Attack Flow
Realistic Targets| Target Path | Impact |
|-------------|--------|
| Proof of ConceptFilesThree files are provided in the
Reproduction Steps
Observed Output
Suggested FixOption 1: Reject path traversal in
|
v0.16.5
patch
Dependencies (18)
+ 10 more |
|
v0.16.4
patch
1 CVE
CVE-2026-34783
GHSA-j6v5-g24h-vg4j
GO-2026-5452
Apr 01, 2026
Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
8.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
High
SummaryA path traversal vulnerability in Ferret's ExploitationThe attacker hosts a malicious website. The victim is an operator running Ferret to scrape it. The operator writes a standard scraping query that saves scraped files using filenames from the website -- a completely normal and expected pattern. Attack Flow
Realistic Targets| Target Path | Impact |
|-------------|--------|
| Proof of ConceptFilesThree files are provided in the
Reproduction Steps
Observed Output
Suggested FixOption 1: Reject path traversal in
|
v0.16.4
patch
Dependencies (18)
+ 10 more |
|
v0.16.3
patch
1 CVE
CVE-2026-34783
GHSA-j6v5-g24h-vg4j
GO-2026-5452
Apr 01, 2026
Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
8.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
High
SummaryA path traversal vulnerability in Ferret's ExploitationThe attacker hosts a malicious website. The victim is an operator running Ferret to scrape it. The operator writes a standard scraping query that saves scraped files using filenames from the website -- a completely normal and expected pattern. Attack Flow
Realistic Targets| Target Path | Impact |
|-------------|--------|
| Proof of ConceptFilesThree files are provided in the
Reproduction Steps
Observed Output
Suggested FixOption 1: Reject path traversal in
|
v0.16.3
patch
Dependencies (18)
+ 10 more |
|
v0.16.2
patch
1 CVE
CVE-2026-34783
GHSA-j6v5-g24h-vg4j
GO-2026-5452
Apr 01, 2026
Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
8.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
High
SummaryA path traversal vulnerability in Ferret's ExploitationThe attacker hosts a malicious website. The victim is an operator running Ferret to scrape it. The operator writes a standard scraping query that saves scraped files using filenames from the website -- a completely normal and expected pattern. Attack Flow
Realistic Targets| Target Path | Impact |
|-------------|--------|
| Proof of ConceptFilesThree files are provided in the
Reproduction Steps
Observed Output
Suggested FixOption 1: Reject path traversal in
|
v0.16.2
patch
Dependencies (18)
+ 10 more |
|
v0.16.1
patch
1 CVE
CVE-2026-34783
GHSA-j6v5-g24h-vg4j
GO-2026-5452
Apr 01, 2026
Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
8.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
High
SummaryA path traversal vulnerability in Ferret's ExploitationThe attacker hosts a malicious website. The victim is an operator running Ferret to scrape it. The operator writes a standard scraping query that saves scraped files using filenames from the website -- a completely normal and expected pattern. Attack Flow
Realistic Targets| Target Path | Impact |
|-------------|--------|
| Proof of ConceptFilesThree files are provided in the
Reproduction Steps
Observed Output
Suggested FixOption 1: Reject path traversal in
|
v0.16.1
patch
Dependencies (18)
+ 10 more |
|
v0.16.0
minor
1 CVE
CVE-2026-34783
GHSA-j6v5-g24h-vg4j
GO-2026-5452
Apr 01, 2026
Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
8.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
High
SummaryA path traversal vulnerability in Ferret's ExploitationThe attacker hosts a malicious website. The victim is an operator running Ferret to scrape it. The operator writes a standard scraping query that saves scraped files using filenames from the website -- a completely normal and expected pattern. Attack Flow
Realistic Targets| Target Path | Impact |
|-------------|--------|
| Proof of ConceptFilesThree files are provided in the
Reproduction Steps
Observed Output
Suggested FixOption 1: Reject path traversal in
|
v0.16.0
minor
Dependencies (18)
+ 10 more |
|
v0.16.0-rc.7
pre
1 CVE
CVE-2026-34783
GHSA-j6v5-g24h-vg4j
GO-2026-5452
Apr 01, 2026
Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
8.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
High
SummaryA path traversal vulnerability in Ferret's ExploitationThe attacker hosts a malicious website. The victim is an operator running Ferret to scrape it. The operator writes a standard scraping query that saves scraped files using filenames from the website -- a completely normal and expected pattern. Attack Flow
Realistic Targets| Target Path | Impact |
|-------------|--------|
| Proof of ConceptFilesThree files are provided in the
Reproduction Steps
Observed Output
Suggested FixOption 1: Reject path traversal in
|
v0.16.0-rc.7
pre
Dependencies (18)
+ 10 more |
|
v0.16.0-rc.6
pre
1 CVE
CVE-2026-34783
GHSA-j6v5-g24h-vg4j
GO-2026-5452
Apr 01, 2026
Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
8.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
High
SummaryA path traversal vulnerability in Ferret's ExploitationThe attacker hosts a malicious website. The victim is an operator running Ferret to scrape it. The operator writes a standard scraping query that saves scraped files using filenames from the website -- a completely normal and expected pattern. Attack Flow
Realistic Targets| Target Path | Impact |
|-------------|--------|
| Proof of ConceptFilesThree files are provided in the
Reproduction Steps
Observed Output
Suggested FixOption 1: Reject path traversal in
|
v0.16.0-rc.6
pre
Dependencies (18)
+ 10 more |
|
v0.16.0-rc.5
pre
1 CVE
CVE-2026-34783
GHSA-j6v5-g24h-vg4j
GO-2026-5452
Apr 01, 2026
Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
8.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
High
SummaryA path traversal vulnerability in Ferret's ExploitationThe attacker hosts a malicious website. The victim is an operator running Ferret to scrape it. The operator writes a standard scraping query that saves scraped files using filenames from the website -- a completely normal and expected pattern. Attack Flow
Realistic Targets| Target Path | Impact |
|-------------|--------|
| Proof of ConceptFilesThree files are provided in the
Reproduction Steps
Observed Output
Suggested FixOption 1: Reject path traversal in
|
v0.16.0-rc.5
pre
Dependencies (18)
+ 10 more |
|
v0.16.0-rc.4
pre
1 CVE
CVE-2026-34783
GHSA-j6v5-g24h-vg4j
GO-2026-5452
Apr 01, 2026
Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
8.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
High
SummaryA path traversal vulnerability in Ferret's ExploitationThe attacker hosts a malicious website. The victim is an operator running Ferret to scrape it. The operator writes a standard scraping query that saves scraped files using filenames from the website -- a completely normal and expected pattern. Attack Flow
Realistic Targets| Target Path | Impact |
|-------------|--------|
| Proof of ConceptFilesThree files are provided in the
Reproduction Steps
Observed Output
Suggested FixOption 1: Reject path traversal in
|
v0.16.0-rc.4
pre
Dependencies (18)
+ 10 more |
|
v0.16.0-rc.3
pre
1 CVE
CVE-2026-34783
GHSA-j6v5-g24h-vg4j
GO-2026-5452
Apr 01, 2026
Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
8.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
High
SummaryA path traversal vulnerability in Ferret's ExploitationThe attacker hosts a malicious website. The victim is an operator running Ferret to scrape it. The operator writes a standard scraping query that saves scraped files using filenames from the website -- a completely normal and expected pattern. Attack Flow
Realistic Targets| Target Path | Impact |
|-------------|--------|
| Proof of ConceptFilesThree files are provided in the
Reproduction Steps
Observed Output
Suggested FixOption 1: Reject path traversal in
|
v0.16.0-rc.3
pre
Dependencies (18)
+ 10 more |
|
v0.16.0-rc.2
pre
1 CVE
CVE-2026-34783
GHSA-j6v5-g24h-vg4j
GO-2026-5452
Apr 01, 2026
Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
8.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
High
SummaryA path traversal vulnerability in Ferret's ExploitationThe attacker hosts a malicious website. The victim is an operator running Ferret to scrape it. The operator writes a standard scraping query that saves scraped files using filenames from the website -- a completely normal and expected pattern. Attack Flow
Realistic Targets| Target Path | Impact |
|-------------|--------|
| Proof of ConceptFilesThree files are provided in the
Reproduction Steps
Observed Output
Suggested FixOption 1: Reject path traversal in
|
v0.16.0-rc.2
pre
Dependencies (18)
+ 10 more |
|
v0.16.0-rc.1
pre
1 CVE
CVE-2026-34783
GHSA-j6v5-g24h-vg4j
GO-2026-5452
Apr 01, 2026
Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
8.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
High
SummaryA path traversal vulnerability in Ferret's ExploitationThe attacker hosts a malicious website. The victim is an operator running Ferret to scrape it. The operator writes a standard scraping query that saves scraped files using filenames from the website -- a completely normal and expected pattern. Attack Flow
Realistic Targets| Target Path | Impact |
|-------------|--------|
| Proof of ConceptFilesThree files are provided in the
Reproduction Steps
Observed Output
Suggested FixOption 1: Reject path traversal in
|
v0.16.0-rc.1
pre
Dependencies (18)
+ 10 more |
|
v0.15.0
initial
1 CVE
CVE-2026-34783
GHSA-j6v5-g24h-vg4j
GO-2026-5452
Apr 01, 2026
Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
8.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
High
SummaryA path traversal vulnerability in Ferret's ExploitationThe attacker hosts a malicious website. The victim is an operator running Ferret to scrape it. The operator writes a standard scraping query that saves scraped files using filenames from the website -- a completely normal and expected pattern. Attack Flow
Realistic Targets| Target Path | Impact |
|-------------|--------|
| Proof of ConceptFilesThree files are provided in the
Reproduction Steps
Observed Output
Suggested FixOption 1: Reject path traversal in
|
v0.15.0
initial
Dependencies (16)
+ 8 more |