Back to CVE List

CVE-2026-39822

HIGH SEVERITY

CVSS Score & Metrics

Base Score
7.8 / 10
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Vulnerability Description

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-61
Source
NVD
Vendor
Go standard library
Product
os

External References

Discussion (0)

Add Comment

No comments yet. Be the first!