CVE-2025-8959
HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designated directory boundaries. This vulnerability, identified as CVE-2025-8959, is fixed in go-getter 1.7.9.
Vendor
Product
CWE
Yayın Tarihi
2025-08-15 21:15:37
Güncelleme
2025-12-11 19:56:22
Source Identifier
security@hashicorp.com
KEV Date Added
-