CVE-2026-88922
Received Received - Intake

Privilege Escalation in Go-Getter Archive Decompression

Vulnerability report for CVE-2026-88922, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-20

Assigner: HashiCorp Inc.

Description

The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permission bits. Where extraction is performed by a privileged user, this may allow a local actor to obtain the privileges of the extracting process. This vulnerability (CVE-2026-88922) is fixed in go-getter 1.8.9 and 2.2.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-20
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
hashicorp go-getter to 2.2.3 (inc)
hashicorp go-getter 1.8.9
hashicorp go-getter 2.2.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-281 The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The go-getter library versions up to 1.8.8 and 2.2.3 have a privilege escalation issue in archive decompression. A crafted archive can create extracted files with elevated permission bits. If a privileged user extracts the archive, a local actor could exploit this to gain the privileges of the extracting process.

Detection Guidance

Check the installed version of go-getter using commands like 'go list -m github.com/hashicorp/go-getter' or inspect dependency files (go.mod). If the version is 1.8.8, 2.2.3, or earlier, the system is vulnerable.

Impact Analysis

If you use go-getter to extract archives as a privileged user, an attacker could craft an archive that creates files with elevated permissions. This could allow the attacker to gain elevated privileges on your system.

Compliance Impact

This vulnerability could potentially violate compliance requirements in GDPR and HIPAA by allowing unauthorized privilege escalation. If exploited, it may enable local actors to gain elevated access, compromising data confidentiality and integrity. Privileged extraction processes handling untrusted archives pose the highest risk.

Mitigation Strategies

Upgrade go-getter to version 1.8.9 or 2.2.4 or later. If upgrading is not possible, avoid extracting untrusted archives as privileged users and restrict extraction to secure, isolated destinations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88922. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart