Packer HashiCorp Packer

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in HashiCorp Packer.

By the Year

In 2026 there have been 1 vulnerability in HashiCorp Packer with an average score of 7.1 out of ten. Packer did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2026 as compared to last year.

Year Vulnerabilities Average Score
2026 1 7.10
2025 0 0.00
2024 0 0.00
2023 0 0.00
2022 1 7.80
2021 0 0.00
2020 0 0.00
2019 0 0.00
2018 1 5.30

It may take a day or so for new Packer vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent HashiCorp Packer Security Vulnerabilities

Packer <=1.15.4 Plugin Installer FS Modification CVE-2026-19589
CVE-2026-19589 7.1 - High - August 17, 2026

Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow unintended file system modification and could lead to code execution. A user who installs a plugin from a malicious or compromised source may be affected. This vulnerability (CVE-2026-19589) is fixed in Packer 1.16.0.

Directory traversal

Hashicorp Packer <2.3.1 Unsecure Vagrant Sudoers Enables Escalation
CVE-2022-42717 7.8 - High - October 11, 2022

An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation, non-privileged users on the host can leverage a wildcard in the sudoers configuration to execute arbitrary commands as root.

An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images
CVE-2018-15869 5.3 - Medium - August 25, 2018

An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and therefore not properly validating source software per AWS recommended security best practices, may unintentionally load an undesired and potentially malicious Amazon Machine Image (AMI) from the uncurated public community AMI catalog.

Incorrect Permission Assignment for Critical Resource

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for HashiCorp Packer or by HashiCorp? Click the Watch button to subscribe.

HashiCorp
Vendor

subscribe