CVE-2026-94445
A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's trusted filesystem.
Disjointly, one of the three possible paths to invoke go vet on the playground host did not correctly restrict the execution environment. This permitted a Go process to make a read for an environment configuration file rooted in the playground host's $HOME.
Together, a well-crafted go env file and the go vet invocation could lead to remote code execution in the playground host itself.
This does not affect users of go.dev/play directly; however, it may affect independent deployments of golang.org/x/playground.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Base score: 8.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.36%
- Percentile among all scored CVEs: 28
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1203Exploitation for Client Executionexecution85 % - Primary impact
T1059Command and Scripting Interpreterexecution90 % - Secondary impact
T1005Data from Local Systemcollection70 % - Secondary impact
T1565.001Stored Data Manipulationimpact75 %
Explotación que requiere interacción del usuario (UI:R) con archivo txtar malicioso en Go playground. Logra RCE en host mediante escape de contexto, ejecución de comandos y acceso a archivos del sistema de archivos confiable.
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-20
References
Raw JSON (NVD)
Show
{
"id": "CVE-2026-94445",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-94445",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-09-25T17:08:10.870774Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@golang.org",
"affectedData": [
{
"vendor": "golang.org/x/playground",
"product": "golang.org/x/playground",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "0.0.0-20260924211604-6d73cff14c17",
"versionType": "semver"
}
],
"packageName": "golang.org/x/playground",
"collectionURL": "https://pkg.go.dev",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-09-25T17:17:19.963",
"references": [
{
"url": "https://go.dev/cl/838485",
"source": "security@golang.org"
},
{
"url": "https://go.dev/issue/81737",
"source": "security@golang.org"
}
],
"vulnStatus": "Awaiting Analysis",
"weaknesses": [
{
"type": "Secondary",
"source": "security@golang.org",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's trusted filesystem.\n\n\n\nDisjointly, one of the three possible paths to invoke go vet on the playground host did not correctly restrict the execution environment. This permitted a Go process to make a read for an environment configuration file rooted in the playground host's $HOME.\n\n\n\nTogether, a well-crafted go env file and the go vet invocation could lead to remote code execution in the playground host itself.\n\n\n\n\nThis does not affect users of go.dev/play directly; however, it may affect independent deployments of golang.org/x/playground."
}
],
"lastModified": "2026-09-29T21:36:39.547",
"sourceIdentifier": "security@golang.org"
}