CVE-2026-39817

MEDIUM

Invoking "go tool pack" does not sanitize output paths in cmd/go

Title source: cna
STIX 2.1

Description

The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.

Scores

CVSS v3 5.9
EPSS 0.0001
EPSS Percentile 0.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-787
Status published
Products (3)
Go toolchain/cmd/go < 1.25.10
Go toolchain/cmd/go 1.26.0-0 - 1.26.3
golang/go < 1.25.10
Published May 07, 2026
Tracked Since May 08, 2026