CVE-2026-88922
The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permission bits. Where extraction is performed by a privileged user, this may allow a local actor to obtain the privileges of the extracting process. This vulnerability (CVE-2026-88922) is fixed in go-getter 1.8.9 and 2.2.4.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.7
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
- EPSS probability
- 0.09%
- CWE
- CWE-281
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- HashiCorp Shared library
Weakness type
Related vulnerabilities
- CVE-2023-48240 — XWiki Platform sends cookies to external images in rendered diff and is vulnerable to server side request forgery
- CVE-2020-8913 — Local arbitrary code execution in splitinstall in Android's Play Core
- CVE-2025-7346 — Any unauthenticated attacker can bypass the localhost restrictions posed by the application and utilize this to create
- CVE-2025-34298 — Nagios Log Server < 2024R1.3.2 Set Email Privilege Escalation
- CVE-2025-24337 — WriteFreely through 0.15.1, when MySQL is used, allows local users to discover credentials by reading config.ini.
- CVE-2023-43612 — Hiview has an improper preservation of permissions vulnerability
- CVE-2023-0975 — A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/
- CVE-2021-43816 — Improper Preservation of Permissions in containerd