"go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames
Details
Security vulnerability affects the loki package. The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames.