Description
On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target).
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Directory Traversal
Action: Update Go
AI Analysis

Impact

The vulnerability allows code that passes a path ending in a junction to the Go runtime’s Root.Mkdir or Root.MkdirAll functions to create a directory at the junction target, even if that target lies outside the intended root directory. This behavior enables an attacker who can control the path argument to write files or directories outside the protected area of the application, potentially leading to unauthorized file creation or modification. The weakness can be classified as a path traversal flaw that is exercised through improper validation of symlink‑like Windows junctions.

Affected Systems

Affected software includes the Go standard library packages internal/syscall/windows and os when running on Windows. The bug is exercised by the exported Root.Mkdir and Root.MkdirAll functions when the last component of the path is a junction pointing to an empty location. No version constraints are provided, so any Go build that contains the current implementation of these functions on Windows may be affected.

Risk and Exploitability

No CVSS metric is provided, and the EPSS score is unavailable, so the severity cannot be quantified with these common metrics. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local or remote execution of Go code that provides a junction path to the Root.Mkdir or Root.MkdirAll APIs, allowing the attacker to create directories outside the intended root. Because the exploitation requires the application to use the vulnerable functions, the risk level depends on the privilege level of the running process and on whether user input can influence the path passed to these calls.

Generated by OpenCVE AI on October 9, 2026 at 00:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Go runtime to the latest stable release that contains the fix for this issue
  • Review all uses of os.Mkdir and os.MkdirAll in your codebase and avoid passing paths that end in junctions, or sanitize such paths before the call
  • Configure the execution environment to disallow the creation of junctions inside the application’s working directories or employ filesystem containment controls

Generated by OpenCVE AI on October 9, 2026 at 00:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 01:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22

Thu, 08 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
Description On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target).
Title Root.Mkdir(All) can follow junctions out of the root on Windows in os
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2026-10-08T22:53:58.387Z

Reserved: 2026-06-23T15:10:49.353Z

Link: CVE-2026-56857

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T23:17:01.487

Modified: 2026-10-08T23:17:01.487

Link: CVE-2026-56857

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T01:00:14Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')