CVE-2026-56857: Root.Mkdir(All) can follow junctions out of the root on Windows in os
Published Oct 8, 2026
·Updated
On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target).
Affected Software
1 affected component
Google Go
Event History
Oct 8, 2026
CVE Published
via MITRE·10:53 PM
Data Sourced
via MITRE·10:53 PM
DescriptionWeakness
Data Sourced
via NVD·11:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
How can I determine whether my code is exposed to this behavior?
Review Windows code paths that call Root.Mkdir or Root.MkdirAll where the final path component may be a junction. Exposure requires that the junction point to an empty location outside the intended root.
2
Are directory creations below a junction also affected?
No. The issue applies when the junction is the last path component, such as path/to/junction, and not when creating a descendant such as path/junction/target.