Path Traversal Affecting golang.org/x/playground package, versions >=0.0.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.36% (28th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Path Traversal vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GOLANGORGXPLAYGROUND-20186633
  • published28 Sept 2026
  • disclosed25 Sept 2026
  • creditsplitline

Introduced: 25 Sep 2026

NewCVE-2026-94445  (opens in a new tab)
CWE-23  (opens in a new tab)

How to fix?

A fix was pushed into the master branch but not yet published.

Overview

Affected versions of this package are vulnerable to Path Traversal in the txtar handling in sandbox.go, which writes each archive entry with os.WriteFile to a path taken from the entry name with no containment to the intended directory, and to unrestricted environment inheritance in vetCheckInDir in vet.go, which builds the go vet command environment from os.Environ() and so carries the host's $HOME into the child process. An attacker can execute code on the playground host by submitting an archive whose entry names place a go env configuration file under that $HOME, then having the submission handled through the go vet path, where the inherited $HOME causes that file to be read and its settings applied to the toolchain invocation. Neither half suffices alone, the write escape reaches the host filesystem while only one of the three paths that invoke go vet fails to restrict the environment, and users of go.dev/play are not affected directly, so the exposure falls on independent deployments of the service.

CVSS Base Scores

version 4.0
version 3.1