← Back to CVE List
Vulnerability Intelligence Report
Root escape via symlink plus trailing slash in os

CVE-2026-39822

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.

No Active Exploit Signals
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
EPSS Probability:0.18%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-61 ↗CWE-61: UNIX Symbolic Link (Symlink) Following

Affected Products & Versions

Vendor Product Affected Versions
Go standard library os 0 < 1.25.12 (affected), 1.26.0-0 < 1.26.5 (affected), 1.27.0-0 < 1.27.0-rc.2 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.181%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGo Project · Vendor · USA
Reserved2026-04-07T18:13:03
Published2026-07-08T15:46:27
Last Updated2026-07-08T19:39:17

LINK COPIED TO CLIPBOARD