« Back to list

CVE-2026-94445

Status: Awaiting AnalysisHigh (8.8)—

A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's trusted filesystem.

Disjointly, one of the three possible paths to invoke go vet on the playground host did not correctly restrict the execution environment. This permitted a Go process to make a read for an environment configuration file rooted in the playground host's $HOME.

Together, a well-crafted go env file and the go vet invocation could lead to remote code execution in the playground host itself.

This does not affect users of go.dev/play directly; however, it may affect independent deployments of golang.org/x/playground.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

Explotación que requiere interacción del usuario (UI:R) con archivo txtar malicioso en Go playground. Logra RCE en host mediante escape de contexto, ejecución de comandos y acceso a archivos del sistema de archivos confiable.

Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (1)

⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2026-94445",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-94445",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-25T17:08:10.870774Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@golang.org",
      "affectedData": [
        {
          "vendor": "golang.org/x/playground",
          "product": "golang.org/x/playground",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "0.0.0-20260924211604-6d73cff14c17",
              "versionType": "semver"
            }
          ],
          "packageName": "golang.org/x/playground",
          "collectionURL": "https://pkg.go.dev",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-09-25T17:17:19.963",
  "references": [
    {
      "url": "https://go.dev/cl/838485",
      "source": "security@golang.org"
    },
    {
      "url": "https://go.dev/issue/81737",
      "source": "security@golang.org"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@golang.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's trusted filesystem.\n\n\n\nDisjointly, one of the three possible paths to invoke go vet on the playground host did not correctly restrict the execution environment. This permitted a Go process to make a read for an environment configuration file rooted in the playground host's $HOME.\n\n\n\nTogether, a well-crafted go env file and the go vet invocation could lead to remote code execution in the playground host itself.\n\n\n\n\nThis does not affect users of go.dev/play directly; however, it may affect independent deployments of golang.org/x/playground."
    }
  ],
  "lastModified": "2026-09-29T21:36:39.547",
  "sourceIdentifier": "security@golang.org"
}