Impact
The vulnerability allows code that passes a path ending in a junction to the Go runtime’s Root.Mkdir or Root.MkdirAll functions to create a directory at the junction target, even if that target lies outside the intended root directory. This behavior enables an attacker who can control the path argument to write files or directories outside the protected area of the application, potentially leading to unauthorized file creation or modification. The weakness can be classified as a path traversal flaw that is exercised through improper validation of symlink‑like Windows junctions.
Affected Systems
Affected software includes the Go standard library packages internal/syscall/windows and os when running on Windows. The bug is exercised by the exported Root.Mkdir and Root.MkdirAll functions when the last component of the path is a junction pointing to an empty location. No version constraints are provided, so any Go build that contains the current implementation of these functions on Windows may be affected.
Risk and Exploitability
No CVSS metric is provided, and the EPSS score is unavailable, so the severity cannot be quantified with these common metrics. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local or remote execution of Go code that provides a junction path to the Root.Mkdir or Root.MkdirAll APIs, allowing the attacker to create directories outside the intended root. Because the exploitation requires the application to use the vulnerable functions, the risk level depends on the privilege level of the running process and on whether user input can influence the path passed to these calls.
OpenCVE Enrichment