---
id: CVE-2026-88922
title: >-
  The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a
  privilege escalation issue in its archive decompression handling that may
  allow a crafted archive to cause extracted files to be created with elevated
  permission bit…
summary: >-
  The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a
  privilege escalation issue in its archive decompression handling that may
  allow a crafted archive to cause extracted files to be created with elevated
  permission bit…
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-281
  - CWE-278
vendor: HashiCorp
product: Shared library
affected:
  - shared_library >= 1.0.1 < 2.2.4
published: '2026-09-15'
updated: '2026-09-20'
sourceUpdated: '2026-09-20T01:16:31.763'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88922'
references:
  - url: >-
      https://discuss.hashicorp.com/t/hcsec-2026-39-go-getter-vulnerable-to-a-privilege-escalation-issue-in-its-archive-decompression-handling/77752
    label: security@hashicorp.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-88922.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-88922'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2534192'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-88922'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88922'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68255'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68259'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68261'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68251'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68281'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-20T00:40:26.832117Z'
epss: 0.00086
epssPercentile: 0.00397
ingestedAt: '2026-09-15T20:44:02.607Z'
patched:
  - hardened_images
---

## Overview

The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permission bits. Where extraction is performed by a privileged user, this may allow a local actor to obtain the privileges of the extracting process. This vulnerability (CVE-2026-88922) is fixed in go-getter 1.8.9 and 2.2.4.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, Red Hat Hardened Images, Red Hat Trusted Artifact Signer · no fix planned: Exploit Intelligence, Red Hat Hardened Images, Red Hat Trusted Artifact Signer · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-88922.json)
- **RHSA-2026:68255** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68255)
- **RHSA-2026:68259** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68259)
- **RHSA-2026:68261** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68261)
- **RHSA-2026:68251** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68251)
- **RHSA-2026:68281** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68281)
