CVE-2026-39817
The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa
The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.
MEDIUM · CVSS 5.9
EPSS 5e-05
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0