A vulnerability was found in Google Go up to 1.23.8/1.24.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file src/os/root.go. The manipulation leads to path traversal.

This vulnerability is handled as CVE-2025-22873. The attack may be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component.