CVE-2026-4660
ADVISORY - githubSummary
HashiCorp's go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package.
Common Weakness Enumeration (CWE)
Exposure of Sensitive Information to an Unauthorized Actor
Exposure of Sensitive Information to an Unauthorized Actor
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
NIST
3.9
CVSS SCORE
7.5highGitHub
3.9
CVSS SCORE
7.5highDebian
-
Ubuntu
-
CVSS SCORE
N/AmediumRed Hat
3.9
CVSS SCORE
7.5highChainguard
CGA-hjr7-vxf9-rgpc
-
minimos
MINI-356c-wvxq-q87v
-
minimos
MINI-4qhh-466x-cjcq
-
minimos
MINI-555x-v2x6-ww59
-
minimos
MINI-59fg-jpw8-j49h
-
minimos
MINI-5q5f-gvmc-23r6
-
minimos
MINI-6hx6-pc84-hmcx
-
minimos
MINI-6m27-4vmx-gwfx
-
minimos
MINI-7263-f7rp-hmv4
-
minimos
MINI-7hfr-mgrm-rvwr
-
minimos
MINI-8fxc-p5q8-759x
-
minimos
MINI-9v6q-jfvj-cppg
-
minimos
MINI-fcm2-ghx5-92gh
-
minimos
MINI-pj26-3243-358v
-
minimos
MINI-q325-phc5-64jf
-
minimos
MINI-qrjx-p53h-96wr
-
minimos
MINI-vc6w-w629-992r
-