While working on the cortex project, I found a vulnerability in the mapstructure package GHSA-fv92-fjc5-jj9h. This issue could lead to sensitive information being leaked in logs when using WeakDecode. The vulnerability is fixed in version 2.3.0, and it’s recommended to upgrade.
CVE Link
CVE Report