Path Traversal Vulnerability in HashiCorp Go-Getter Product
CVE-2026-19585
5.3MEDIUM
What is CVE-2026-19585?
The Go-Getter tool by HashiCorp is susceptible to a path traversal vulnerability that affects versions prior to 1.8.10 and 2.2.5 for go-getter/v2. This issue arises during the handling of directory downloads from S3 and Google Cloud Storage (GCS), enabling malicious actors to potentially write files outside of the intended destination. Users are advised to upgrade to the fixed versions to mitigate this security risk.
Affected Version(s)
Shared library 64 bit 1.0.1 < 2.2.5
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was reported to HashiCorp by Kris Kennaway.