← Back

CVE-2025-22873

nvd nist
Published: Feb 4, 2026Modified: Feb 10, 2026

JSON object

Loading...
3.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Exploitability: 2.0 / Impact: 1.4
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For example, Root.Open("../") would open the parent directory of the Root. This escape only permits opening the parent directory itself, not ancestors of the parent or files contained within the parent.

Affected (2)

Products: Golang: Go
1 product
Go
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Golang
Before 1.23.9
From 1.24.0 to 1.24.3

References (5)

Source: security@golang.org
PatchProduct
Source: security@golang.org
Issue TrackingVendor Advisory
Source: security@golang.org
Mailing ListRelease Notes
Source: security@golang.org
Vendor AdvisoryIssue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory

Timeline

No history available yet.