๐Ÿ” CVE Alert

CVE-2026-19585

MEDIUM 5.3

Go-getter vulnerable to a path traversal in S3/GCS directory download handling

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

HashiCorp go-getter versions before 1.8.10 and go-getter/v2 versions before 2.2.5 are vulnerable to path traversal during S3 and GCS directory downloads, which may allow files to be written outside the requested destination. This vulnerability (CVE-2026-19585) is fixed in go-getter 1.8.10 and go-getter/v2 2.2.5.

CWE CWE-22
Vendor hashicorp
Product shared library
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for hashicorp shared library

Be the first to know when new medium vulnerabilities affecting hashicorp shared library are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

HashiCorp / Shared library
1.0.1 < 2.2.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
discuss.hashicorp.com: https://discuss.hashicorp.com/t/hcsec-2026-44-go-getter-vulnerable-to-a-path-traversal-in-s3-gcs-directory-download-handling/77819

Credits

This issue was reported to HashiCorp by Kris Kennaway.