---
id: CVE-2026-56857
title: >-
  On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction
  pointing to an empty location, the operation can create a directory at the
  junction target even when that target is located outside the root
summary: >-
  On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction
  pointing to an empty location, the operation can create a directory at the
  junction target even when that target is located outside the root. This only
  applies to o…
severity: none
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T23:17:01.487'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-56857'
references:
  - url: 'https://go.dev/cl/847305'
    label: security@golang.org
  - url: 'https://go.dev/issue/81739'
    label: security@golang.org
  - url: 'https://groups.google.com/g/golang-announce/c/U2fTuyDJznI'
    label: security@golang.org
  - url: 'https://pkg.go.dev/vuln/GO-2026-6604'
    label: security@golang.org
tags:
  - nvd
ingestedAt: '2026-10-09T00:19:50.973Z'
---

## Overview

On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
