HIGH7.5
GHSA-wjrx-6529-hcj3
HashiCorp go-getter Vulnerable to Symlink Attacks
Quick fix
GHSA-wjrx-6529-hcj3 — github.com/hashicorp/go-getter: upgrade to the fixed version with the command below.
go get github.com/hashicorp/go-getter@v1.7.9Details
HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designated directory boundaries. This vulnerability, identified as CVE-2025-8959, is fixed in go-getter 1.7.9.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/go-getter
Introduced in:
0Fixed in: 1.7.9Fix
go get github.com/hashicorp/go-getter@v1.7.9References
- https://nvd.nist.gov/vuln/detail/CVE-2025-8959[ADVISORY]
- https://github.com/hashicorp/go-getter/commit/87541b2501c00df5eaedea6acc61a2a4a4efa5b7[WEB]
- https://discuss.hashicorp.com/t/hcsec-2025-23-hashicorp-go-getter-vulnerable-to-arbitrary-read-through-symlink-attack/76242[WEB]
- https://github.com/hashicorp/go-getter[PACKAGE]
- https://pkg.go.dev/vuln/GO-2025-3892[WEB]