Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-39817

Опубликовано: 07 мая 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.

A flaw was found in the "go tool pack" subcommand, a component of the Go programming language tools. This vulnerability allows an attacker to craft a malicious archive file. When this archive is extracted using the "pack" subcommand, it can lead to arbitrary file writes on the filesystem, potentially allowing an attacker to create or modify files in unintended locations.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Engine for Kubernetesmulticluster-engine/addon-manager-rhel9Under investigation
Multicluster Engine for Kubernetesmulticluster-engine/backplane-rhel9-operatorUnder investigation
Multicluster Engine for Kubernetesmulticluster-engine/clusterlifecycle-state-metrics-rhel9Under investigation
Multicluster Engine for Kubernetesmulticluster-engine/hypershift-addon-rhel9-operatorUnder investigation
Multicluster Engine for Kubernetesmulticluster-engine/maestro-rhel9Under investigation
Multicluster Engine for Kubernetesmulticluster-engine/managedcluster-import-controller-rhel9Under investigation
Multicluster Engine for Kubernetesmulticluster-engine/multicloud-manager-rhel9Under investigation
Multicluster Engine for Kubernetesmulticluster-engine/placement-rhel9Under investigation
Multicluster Engine for Kubernetesmulticluster-engine/registration-operator-rhel9Under investigation
Multicluster Engine for Kubernetesmulticluster-engine/work-rhel9Under investigation

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2467825cmd/go: golang: Go tool pack: Arbitrary file write via malicious archive extraction

EPSS

Процентиль: 7%
0.0017
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
3 месяца назад

The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.

CVSS3: 5.9
nvd
3 месяца назад

The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.

msrc
3 месяца назад

Invoking "go tool pack" does not sanitize output paths in cmd/go

CVSS3: 5.9
debian
3 месяца назад

The "go tool pack" subcommand (usually used only by the compiler as an ...

CVSS3: 5.9
github
3 месяца назад

The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.

EPSS

Процентиль: 7%
0.0017
Низкий

5.9 Medium

CVSS3