ZeroHour

CVE-2025-8959

CVSS 3.1
7.5 high
EPSS
<1%p44
Published
()
Modified
Description

HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designated directory boundaries. This vulnerability, identified as CVE-2025-8959, is fixed in go-getter 1.7.9.

Vendors
hashicorp
Products
go-getter
Weakness
CWE-59
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.