CVE-2026-56857 Go os.Root 路径穿越漏洞
影响攻击者可绕过根目录限制在任意位置创建目录
该漏洞影响 Go 标准库中的 os.Root 类型。在 Windows 平台上,当 Root.Mkdir 或 Root.MkdirAll 的目标是指向空位置的 junction(目录联接)时,即使该目标位于 root 之外,操作仍会在 junction 目标处创建目录。此问题仅影响路径最后一段为 junction 的操作。
影响范围
受影响组件为 Go 标准库的 os.Root(Windows 平台)。具体受影响版本范围暂无公开信息。
漏洞详情
漏洞类型为路径穿越/目录限制绕过。成因在于 Windows 下 os.Root 对 junction 的解析处理不当,未正确校验 junction 指向的实际目标是否位于 root 范围内。攻击者可通过构造最后一段为 junction 的路径,诱使 Mkdir/MkdirAll 在 root 之外创建目录,从而突破预期的目录边界限制。
利用条件与风险
利用前提是运行于 Windows 平台且使用 os.Root 的 Mkdir/MkdirAll 处理攻击者可控路径。实战中可导致在预期根目录之外创建目录,可能被用于进一步的文件系统操作或权限提升。
修复建议
官方修复方案暂无公开信息,建议关注 Go 官方安全公告并升级至修复版本。临时缓解措施:在 Windows 上避免对不可信路径使用 os.Root 的 Mkdir/MkdirAll,或对路径中的 junction 进行额外校验。
On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target).