📦 Go Getter

by Hashicorp

🔍 What is Go Getter?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-3817

CRITICAL CVSS 9.8 Apr 17, 2024

HashiCorp's go-getter library is vulnerable to argument injection when executing Git commands to discover remote branches. This allows attackers to inject arbitrary arguments into Git commands, potent...

CVE-2022-26945

CRITICAL CVSS 9.8 May 25, 2022

This vulnerability in the go-getter library allows attackers to bypass security controls, switch protocols, and create endless redirects by manipulating custom HTTP response headers. It affects applic...

CVE-2025-8959

HIGH CVSS 7.5 Aug 15, 2025

CVE-2025-8959 is a symlink attack vulnerability in HashiCorp's go-getter library that allows attackers to read files outside the intended download directory by exploiting the subdirectory download fea...

CVE-2024-6257

HIGH CVSS 8.4 Jun 25, 2024

CVE-2024-6257 is a vulnerability in HashiCorp's go-getter library where an attacker can manipulate Git configuration files to execute arbitrary code during Git update operations. This affects any appl...

CVE-2022-30321

HIGH CVSS 8.6 May 25, 2022

This vulnerability in the go-getter library allows attackers to perform path traversal, symlink processing, and command injection attacks, potentially leading to arbitrary file access and remote code ...

CVE-2022-30323

HIGH CVSS 8.6 May 25, 2022

This vulnerability in go-getter library causes a panic (crash) when processing password-protected ZIP files. It affects applications using go-getter up to versions 1.5.11 and 2.0.2 for file retrieval ...