{"schema_version":"1.9.0","id":"GO-2026-6604","published":"2026-10-08T22:31:09Z","modified":"2026-10-08T23:00:13.816942040Z","aliases":["CVE-2026-56857"],"summary":"Root.Mkdir(All) can follow junctions out of the root on Windows in os","details":"On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target).","affected":[{"package":{"name":"stdlib","ecosystem":"Go","purl":"pkg:golang/stdlib"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.26.9"},{"introduced":"1.27.0-0"},{"fixed":"1.27.2"}]}],"ecosystem_specific":{"imports":[{"goos":["windows"],"path":"os","symbols":["Root.Chmod","Root.Chown","Root.Chtimes","Root.Lchown","Root.Link","Root.Mkdir","Root.MkdirAll","Root.Remove","Root.RemoveAll","Root.Rename","Root.Symlink","doInRoot","rootMkdirAll"]},{"goos":["windows"],"path":"internal/syscall/windows","symbols":["Mkdirat"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6604.json"}}],"references":[{"type":"FIX","url":"https://go.dev/cl/847305"},{"type":"REPORT","url":"https://go.dev/issue/81739"},{"type":"WEB","url":"https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"}],"database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-6604"},"credits":[{"name":"Daniele Ballarini"}]}