Executive brief
A vulnerability in the Go programming language's 'pack' tool could allow a malicious archive to write files to unintended locations on a computer. This tool is typically used internally by the Go compiler, but if a user is tricked into manually extracting a specially crafted archive, it could overwrite sensitive system or application files. This could lead to unauthorized system changes or a compromise of the development environment.
Technical details
A path traversal vulnerability exists in the 'go tool pack' subcommand, which serves as a minimal version of the Unix 'ar' utility. The tool fails to sanitize output filenames during extraction, allowing an attacker to provide a malicious archive that writes files to arbitrary locations on the filesystem. While primarily used as an internal compiler tool with trusted inputs, manual invocation on untrusted archives poses a risk. The vulnerability is addressed by modifying 'pack' to refuse extraction of files containing directory components. Patches are available in Go versions 1.25.10 and 1.26.3.
Affected products
- Google Go < 1.25.10, >= 1.26.0 < 1.26.3
Timeline
- 2026-04-15: disclosed: Issue opened on Go GitHub repository
- 2026-05-07: advisory: NVD and Go Project published advisory