CVE-2026-39817 - Invoking "go tool pack" does not sanitize output paths in cmd/go
CVE ID :CVE-2026-39817
Published : May 7, 2026, 7:41 p.m. | 35 minutes ago
Description :The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : May 7, 2026, 7:41 p.m. | 35 minutes ago
Description :The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...