Vulnerability GO-2026-4979
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
5 months ago
May 07, 2026 at 07:21 PM UTC
Invoking "go tool pack" does not sanitize output paths in cmd/go
<1.25.10
<1.25.10
Summary
Invoking "go tool pack" does not sanitize output paths in cmd/go
Details
The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
9 hours ago
Checksum bypass for golang.org/fips140 in cmd/go
<1.26.9 GO-2026-6601
<1.26.9 GO-2026-6601
Unknown
9 hours ago
Checksum database bypass for golang.org/toolchain in cmd/go
<1.26.9 GO-2026-6602
<1.26.9 GO-2026-6602
Unknown
1 month ago
Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
<1.25.13 GO-2026-6179
<1.25.13 GO-2026-6179
Unknown
1 month ago
Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
<1.25.13 GO-2026-6180
<1.25.13 GO-2026-6180
Unknown
5 months ago
Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
<1.25.10 GO-2026-4978
<1.25.10 GO-2026-4978
Impacted packages
Timeline
Published
5 months ago
May 07, 2026 at 07:21 PM UTC
Last Modified
16 days ago
September 22, 2026 at 10:41 AM UTC