Junglewise Threat Intelligence

CVE-2026-39817: Google Go arbitrary file write in go tool pack

CVE-2026-39817 · Severity: medium · CVSS 5.9 · Published 2026-05-07

Technologies: toolchain (Go). Vendors: Google, Go.

Executive brief

A vulnerability in the Go programming language's 'pack' tool could allow a malicious archive to write files to unintended locations on a computer. This tool is typically used internally by the Go compiler, but if a user is tricked into manually extracting a specially crafted archive, it could overwrite sensitive system or application files. This could lead to unauthorized system changes or a compromise of the development environment.

Technical details

A path traversal vulnerability exists in the 'go tool pack' subcommand, which serves as a minimal version of the Unix 'ar' utility. The tool fails to sanitize output filenames during extraction, allowing an attacker to provide a malicious archive that writes files to arbitrary locations on the filesystem. While primarily used as an internal compiler tool with trusted inputs, manual invocation on untrusted archives poses a risk. The vulnerability is addressed by modifying 'pack' to refuse extraction of files containing directory components. Patches are available in Go versions 1.25.10 and 1.26.3.

Affected products

  • Google Go < 1.25.10, >= 1.26.0 < 1.26.3

Timeline

  • 2026-04-15: disclosed: Issue opened on Go GitHub repository
  • 2026-05-07: advisory: NVD and Go Project published advisory

References

Related threats