HIGH
golang.org/x/playground
CVE published 2026-09-25
CVE-2026-94445
CVE-2026-94445 was published on 2026-09-25T17:17:19.963Z and has not been modified since then. The NVD entry is currently 8.8 HIGH. A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's trusted filesystem. Disjointly, one of the three possible paths to invoke go vet on the playground host did not correctly restrict the execution environment. This [truncated]