CVE-2026-88922

Source
https://cve.org/CVERecord?id=CVE-2026-88922
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88922.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-88922
Published
2026-09-15T19:45:07Z
Modified
2026-09-17T03:47:17Z
Severity
  • 6.7 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Go-getter vulnerable to a privilege escalation issue in its archive decompression handling
Details

The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permission bits. Where extraction is performed by a privileged user, this may allow a local actor to obtain the privileges of the extracting process. This vulnerability (CVE-2026-88922) is fixed in go-getter 1.8.9 and 2.2.4.

Database specific
{
    "cna_assigner": "HashiCorp",
    "cwe_ids": [
        "CWE-281"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88922.json"
}
References

Affected packages

Git / github.com/hashicorp/go-getter

Affected ranges

Type
GIT
Repo
https://github.com/hashicorp/go-getter
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.0.1"
        },
        {
            "fixed": "2.2.4"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

cmd/go-getter/v2.*
cmd/go-getter/v2.0.2
cmd/go-getter/v2.1.1
cmd/go-getter/v2.2.0
cmd/go-getter/v2.2.1
cmd/go-getter/v2.2.2
cmd/go-getter/v2.2.3
gcs/v2.*
gcs/v2.0.2
gcs/v2.1.0
gcs/v2.1.1
gcs/v2.2.0
gcs/v2.2.1
gcs/v2.2.2
gcs/v2.2.3
s3/v2.*
s3/v2.0.2
s3/v2.1.0
s3/v2.1.1
s3/v2.2.0
s3/v2.2.1
s3/v2.2.2
s3/v2.2.3
v1.*
v1.0.1
v1.0.2
v1.0.3
v1.1.0
v1.2.0
v1.3.0
v1.4.0
v1.4.1
v2.*
v2.0.0
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.2.0
v2.2.1
v2.2.2
v2.2.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88922.json"