Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-92mm-2pjq-r785

Опубликовано: 09 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

HashiCorp's go-getter library may allow arbitrary file reads

HashiCorp's go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package.

Пакеты

Наименование

github.com/hashicorp/go-getter

go
Затронутые версииВерсия исправления

< 1.8.6

1.8.6

EPSS

Процентиль: 45%
0.00583
Низкий

7.5 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This vulnerability, CVE-2026-4660, is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package.

CVSS3: 7.5
redhat
4 месяца назад

HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This vulnerability, CVE-2026-4660, is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package.

CVSS3: 7.5
nvd
4 месяца назад

HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This vulnerability, CVE-2026-4660, is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package.

CVSS3: 7.5
debian
4 месяца назад

HashiCorp\u2019s go-getter library up to v1.8.5 may allow arbitrary fi ...

EPSS

Процентиль: 45%
0.00583
Низкий

7.5 High

CVSS3

Дефекты

CWE-200