
Demo consumer for gin v1.7.0 (CVE-2023-29401) — Context.FileAttachment with user input. endorctl scan target.
Demo consumer pinned to github.com/gin-gonic/gin v1.7.0 (vulnerable to
CVE-2023-29401). The /download/:filename handler passes user input
directly to Context.FileAttachment — the exploit-condition pattern
Endor flags as exploitable.