CyberRota
← Ana sayfaya dön

CVE-2026-39817

MEDIUM · CVSS 5.9 EPSS %0.01

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-05-07T20:16:42.983 · Çekilme zamanı: 2026-06-06T18:00:32.186064+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-39817
Severity
MEDIUM
CVSS
5.9
EPSS
%0.01

Orijinal NVD Açıklaması

The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.