CVE-2026-4660
ADVISORY - githubSummary
HashiCorp's go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package.
Common Weakness Enumeration (CWE)
Exposure of Sensitive Information to an Unauthorized Actor
Exposure of Sensitive Information to an Unauthorized Actor
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
NIST
3.9
CVSS SCORE
7.5highGitHub
3.9
CVSS SCORE
7.5highDebian
-
Ubuntu
-
CVSS SCORE
N/AmediumRed Hat
3.9
CVSS SCORE
7.5highChainguard
CGA-hjr7-vxf9-rgpc
-
minimos
MINI-32v7-9xfc-cww2
-
minimos
MINI-356c-wvxq-q87v
-
minimos
MINI-4624-8hpg-rcj5
-
minimos
MINI-49cx-j3r2-r26m
-
minimos
MINI-4qhh-466x-cjcq
-
minimos
MINI-555x-v2x6-ww59
-
minimos
MINI-59fg-jpw8-j49h
-
minimos
MINI-5q5f-gvmc-23r6
-
minimos
MINI-6hx6-pc84-hmcx
-
minimos
MINI-6m27-4vmx-gwfx
-
minimos
MINI-7263-f7rp-hmv4
-
minimos
MINI-77q7-qp5r-8x5j
-
minimos
MINI-7hfr-mgrm-rvwr
-
minimos
MINI-8fxc-p5q8-759x
-
minimos
MINI-93vf-2w7h-3m9g
-
minimos
MINI-98vv-6rw2-jh2p
-
minimos
MINI-9v6q-jfvj-cppg
-
minimos
MINI-c929-w75p-2w88
-
minimos
MINI-cxvr-wccp-5wwp
-
minimos
MINI-fcm2-ghx5-92gh
-
minimos
MINI-hhcr-pr5j-7rvq
-
minimos
MINI-m3p5-vm28-jmr7
-
minimos
MINI-mrv7-3h6j-mhv8
-
minimos
MINI-pj26-3243-358v
-
minimos
MINI-pqrj-r9p9-cwpm
-
minimos
MINI-q325-phc5-64jf
-
minimos
MINI-q7mm-8jmg-gffg
-
minimos
MINI-qrjx-p53h-96wr
-
minimos
MINI-rv5j-g8j3-j8c9
-
minimos
MINI-v9qp-g62x-5gmm
-
minimos
MINI-vc6w-w629-992r
-