CVE-2026-56857
Received Received - Intake

Go Root.MkdirAll Directory Creation Outside Root via Junction

Vulnerability report for CVE-2026-56857, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Go Project

Description

On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
Go standard library os 0
Go standard library os 1.27.0-0
Go standard library internal/syscall/windows 0
Go standard library internal/syscall/windows 1.27.0-0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Go's filesystem operations on Windows. When using Root.Mkdir or Root.MkdirAll to create a directory through a junction (a type of symbolic link), the operation may incorrectly create a directory at the junction's target location even if that target is outside the intended root directory. This only happens when the last path component is a junction.

Detection Guidance

This vulnerability is specific to Go's filesystem operations on Windows and does not have direct network detection methods. Check Go applications using Root.Mkdir or Root.MkdirAll with junction targets. Review filesystem logs for unexpected directory creation outside intended paths.

Impact Analysis

This could allow unauthorized directory creation outside intended boundaries, potentially leading to filesystem corruption, privilege escalation, or bypassing security controls that rely on path restrictions.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it pertains to filesystem operations on Windows and does not involve data exposure or unauthorized access to sensitive information.

Mitigation Strategies

Update Go to the latest version where this issue is patched. Audit Go applications for unsafe use of Root.Mkdir or Root.MkdirAll with junction targets. Restrict filesystem permissions to limit directory creation outside intended paths.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56857. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart