go-getter PrivEsc via Archive Decompress (<=1.8.8/2.2.3)
CVE-2026-88922 Published on September 15, 2026
Go-getter vulnerable to a privilege escalation issue in its archive decompression handling
The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permission bits. Where extraction is performed by a privileged user, this may allow a local actor to obtain the privileges of the extracting process. This vulnerability (CVE-2026-88922) is fixed in go-getter 1.8.9 and 2.2.4.
Weakness Type
Improper Preservation of Permissions
The software does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.
Affected Versions
HashiCorp Shared library:- Version 1.0.1 and below 2.2.4 is affected.