HashiCorpCVE-2026-88922
HashiCorp Shared library: privilege escalation
Medium6.7CVE-2026-88922 · Published Sep 15, 2026 · updated Sep 20, 2026
The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permission bits. Where extraction is performed by a privileged user, this may allow a local actor to obtain the privileges of the extracting process. This vulnerability (CVE-2026-88922) is fixed in go-getter 1.8.9 and 2.2.4.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Shared library Product | >= 1.0.1, < 2.2.4 | 2.2.4 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-281
More HashiCorp advisories
All HashiCorp| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 10 | HashiCorp Tooling: information disclosure | High7.7 | 0.43.0 |
| Sep 10 | Consul and Consul Enterprise are vulnerable to an authorization bypass in the... | High7.1 | 2.0.4+1 more |
| Sep 10 | HashiCorp Consul: improper authorization | High8.3 | 2.0.4+1 more |
| Sep 10 | HashiCorp Consul: denial of service | Medium6.5 | 2.0.4+1 more |
| Sep 10 | HashiCorp Consul: improper authorization | Medium5.4 | 2.0.4+1 more |
| Aug 24 | HashiCorp Vault: insecure direct object reference | Medium6.8 | 2.0.4+1 more |