Privilege Escalation Vulnerability in Go-Getter Library by HashiCorp
CVE-2026-88922

6.7MEDIUM

Key Information:

Vendor

Hashicorp

Vendor
CVE Published:
15 September 2026

What is CVE-2026-88922?

The Go-Getter library, utilized for downloading files and managing archives, contains a vulnerability that affects its archive decompression handling. This flaw can be exploited to escalate privileges, where a specially crafted archive can lead to extracted files being created with elevated permissions. Specifically, if extraction is executed by a user with privileges, a local actor could gain access to the privileges of that user, posing a significant security risk. The issue has been addressed in Go-Getter versions 1.8.9 and 2.2.4, making it crucial for users to upgrade to these versions to mitigate potential threats.

Affected Version(s)

Shared library 64 bit 1.0.1 < 2.2.4

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was reported to HashiCorp by Kris Kennaway.
.