CWE-278
CVEs classified under CWE-278, newest first.
2 CVEsRSS
CVE-2026-88922Medium· 6.7The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permission bit…
The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permission bit…
▾ SunlitHashiCorp · Shared libraryEPSS 0.09%via NVD
CVE-2026-71477Medium· 6.7mise manages dev tools like node, python, cmake, and terraform
mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.7.1, release tar archives record mise/bin/mise with user and group ID 1001 and packaging/standalone/install.envsubst extracts and moves it without normalizing …
▾ SunlitEPSS 0.10%via NVD