OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-94445

HIGH · CVSS 8.8 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability allows a malicious txtar to escape its execution context, enabling arbitrary writes to the trusted filesystem of the playground host. Additionally, a misconfigured invocation of the go vet command could permit remote code execution through a specially crafted environment configuration file. Organizations using independent deployments of golang.org/x/playground should prioritize addressing this issue to mitigate potential security risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-94445
Severity
HIGH
CVSS
8.8
EPSS
0.36%

Original NVD Description

A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's trusted filesystem. Disjointly, one of the three possible paths to invoke go vet on the playground host did not correctly restrict the execution environment. This permitted a Go process to make a read for an environment configuration file rooted in the playground host's $HOME. Together, a well-crafted go env file and the go vet invocation could lead to remote code execution in the playground host itself. This does not affect users of go.dev/play directly; however, it may affect independent deployments of golang.org/x/playground.