Junglewise Threat Intelligence

CVE-2026-88922: go-getter privilege escalation in archive decompression

CVE-2026-88922 · Severity: medium · CVSS 6.7 · Published 2026-09-15

Vendors: HashiCorp.

Executive brief

go-getter is a library used by HashiCorp tools to download and extract files and archives. A flaw in its archive extraction logic allows crafted archives to create files with elevated permission bits, potentially enabling a local attacker to gain the privileges of the user performing the extraction. The risk is highest when untrusted archives are extracted by privileged users.

Technical details

The vulnerability exists in go-getter's archive decompression handling, which applies permission metadata from archive entries without restricting them to standard read, write, and execute permissions. This allows an attacker to craft a malicious archive containing entries with elevated permission bits (such as setuid/setgid bits). When extracted by a privileged user, a local actor with access to the destination directory can exploit these elevated permissions to obtain the privileges of the extracting process. The attack requires the extraction of untrusted or attacker-controlled archives and local filesystem access to the extraction destination. The fix, available in go-getter 1.8.9 and 2.2.4, restricts extracted files to only standard permissions.

Affected products

  • HashiCorp go-getter up to 1.8.8 and 2.2.3

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Fixed in go-getter 1.8.9 and 2.2.4

References

Related threats