"go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames
Details
Security vulnerability affects the kube-state-metrics-fips package. The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames.