On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target).
{
"review_status": "REVIEWED",
"url": "https://pkg.go.dev/vuln/GO-2026-6604"
}{
"imports": [
{
"goos": [
"windows"
],
"path": "os",
"symbols": [
"Root.Chmod",
"Root.Chown",
"Root.Chtimes",
"Root.Lchown",
"Root.Link",
"Root.Mkdir",
"Root.MkdirAll",
"Root.Remove",
"Root.RemoveAll",
"Root.Rename",
"Root.Symlink",
"doInRoot",
"rootMkdirAll"
]
},
{
"goos": [
"windows"
],
"path": "internal/syscall/windows",
"symbols": [
"Mkdirat"
]
}
]
}