A vulnerability, which was classified as critical, was found in cmd-go up to 1.25.9/1.26.2 on Go. Affected by this vulnerability is an unknown functionality of the component Archive Handler. The manipulation results in path traversal.
This vulnerability is cataloged as CVE-2026-39817. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.