File System Modification Risk in Packer by HashiCorp
CVE-2026-19589
7.1HIGH
What is CVE-2026-19589?
Packer, developed by HashiCorp, is affected by a vulnerability in its third-party plugin installer. This flaw can enable unintended modifications to the file system, potentially allowing code execution if a user installs a plugin from a non-trustworthy or compromised source. Users are advised to upgrade to Packer version 1.16.0 or later to mitigate this risk and enhance their security posture.
Affected Version(s)
Packer 64 bit 1.7.0 < 1.16.0