UNIX symbolic link following in Go programming language - CVE-2026-39819
Published: July 31, 2026
Vulnerability details
The vulnerability allows a local user to overwrite arbitrary files.
The vulnerability exists due to improper link resolution in the go bug command temporary file handling when writing to predictable file names in the system temporary directory. A local user can create a symlink with a predictable temporary file name to overwrite arbitrary files.