CVE-2025-8959: Hashicorp Go-Getter
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designated directory boundaries. This vulnerability, identified as CVE-2025-8959, is fixed in go-getter 1.7.9.
Affected products
- Hashicorp Go-Getter: before 1.7.9 (fixed in 1.7.9)
Published 2025-08-15. Last modified 2026-06-17.