cve/2025/CVE-2025-8959.md
2025-09-29 21:09:30 +02:00

810 B

CVE-2025-8959

Description

HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designated directory boundaries. This vulnerability, identified as CVE-2025-8959, is fixed in go-getter 1.7.9.

POC

Reference

No PoCs from references.

Github