
We found results for “”
CVE-2025-8959
Good to know:


Date: August 15, 2025
HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designated directory boundaries. This vulnerability, identified as CVE-2025-8959, is fixed in go-getter 1.7.9.
Severity Score
Related Resources (7)
Severity Score
Weakness Type (CWE)
Improper Link Resolution Before File Access ('Link Following')
CWE-59Top Fix

Upgrade Version
Upgrade to version github.com/hashicorp/go-getter - v1.7.9;github.com/hashicorp/go-getter - v1.7.9
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | LOW |
Integrity (I): | LOW |
Availability (A): | HIGH |