{"id":"CVE-2026-88922","title":"The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permission bit…","summary":"The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permission bit…","severity":"medium","cvss":6.7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-281","CWE-278"],"vendor":"HashiCorp","product":"Shared library","affected":["shared_library >= 1.0.1 < 2.2.4"],"published":"2026-09-15","updated":"2026-09-20","sourceUpdated":"2026-09-20T01:16:31.763","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-88922","references":[{"url":"https://discuss.hashicorp.com/t/hcsec-2026-39-go-getter-vulnerable-to-a-privilege-escalation-issue-in-its-archive-decompression-handling/77752","label":"security@hashicorp.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-88922.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-88922"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2534192"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-88922"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88922"},{"url":"https://access.redhat.com/errata/RHSA-2026:68255"},{"url":"https://access.redhat.com/errata/RHSA-2026:68259"},{"url":"https://access.redhat.com/errata/RHSA-2026:68261"},{"url":"https://access.redhat.com/errata/RHSA-2026:68251"},{"url":"https://access.redhat.com/errata/RHSA-2026:68281"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-20T00:40:26.832117Z"},"epss":0.00086,"epssPercentile":0.00396,"ingestedAt":"2026-09-15T20:44:02.607Z","patched":["hardened_images"],"slug":"CVE-2026-88922","body":"## Overview\n\nThe go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permission bits. Where extraction is performed by a privileged user, this may allow a local actor to obtain the privileges of the extracting process. This vulnerability (CVE-2026-88922) is fixed in go-getter 1.8.9 and 2.2.4.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, Red Hat Hardened Images, Red Hat Trusted Artifact Signer · no fix planned: Exploit Intelligence, Red Hat Hardened Images, Red Hat Trusted Artifact Signer · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-88922.json)\n- **RHSA-2026:68255** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68255)\n- **RHSA-2026:68259** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68259)\n- **RHSA-2026:68261** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68261)\n- **RHSA-2026:68251** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68251)\n- **RHSA-2026:68281** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68281)","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":36.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}