VDB
Sign up
HIGH7.5

GHSA-wjrx-6529-hcj3

HashiCorp go-getter Vulnerable to Symlink Attacks

Quick fix

GHSA-wjrx-6529-hcj3 — github.com/hashicorp/go-getter: upgrade to the fixed version with the command below.

go get github.com/hashicorp/go-getter@v1.7.9

Details

HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designated directory boundaries. This vulnerability, identified as CVE-2025-8959, is fixed in go-getter 1.7.9.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/hashicorp/go-getter
Introduced in: 0Fixed in: 1.7.9
Fixgo get github.com/hashicorp/go-getter@v1.7.9

References