๐Ÿ” CVE Alert

CVE-2026-88922

MEDIUM 6.7

Go-getter vulnerable to a privilege escalation issue in its archive decompression handling

CVSS Score
6.7
EPSS Score
0.0%
EPSS Percentile
0th

The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permission bits. Where extraction is performed by a privileged user, this may allow a local actor to obtain the privileges of the extracting process. This vulnerability (CVE-2026-88922) is fixed in go-getter 1.8.9 and 2.2.4.

CWE CWE-281
Vendor hashicorp
Product shared library
Published Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for hashicorp shared library

Be the first to know when new medium vulnerabilities affecting hashicorp shared library are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

HashiCorp / Shared library
1.0.1 < 2.2.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
discuss.hashicorp.com: https://discuss.hashicorp.com/t/hcsec-2026-39-go-getter-vulnerable-to-a-privilege-escalation-issue-in-its-archive-decompression-handling/77752

Credits

This issue was reported to HashiCorp by Kris Kennaway.