CVE 5.9 MEDIUM

Invoking “go tool pack” does not sanitize output paths in cmd/go_CVE-2026-39817

5.9 / 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N

Description

The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.

Basic Information

ID CVE-2026-39817
Source Go
Published May 7, 2026 at 19:41
Modified May 8, 2026 at 21:29

Affected Product

Vendor Go toolchain
Product cmd/go
Affected Versions Go toolchain cmd/go 0
Go toolchain cmd/go 1.26.0-0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.