This code contains security issue, can a tool spot it? Now caught by gosec G111: Potential directory traversal securego/gosec#569 (comment)