This exact thing is being discussed https://github.com/golang/go/issues/25849 here. Maybe take a look
Though also, "we've seen this cause exploits in the wild multiple times, let's just let this footgun sit for 3 years".
They could have at least added a documentation note to the archive/tar page that there's a security issue you have to handle, which is what the unsafe version of the rust unarchive methods do. 3 years of not even updating docs is kinda unfortunate.