HashiCorp go-getter 版本低于 1.8.10 以及 go-getter/v2 版本低于 2.2.5 的软件中存在路径遍历漏洞。在从 S3 和 GCS 下载目录时,攻击者可利用此漏洞将文件写入非预期目标路径,从而可能导致非法文件覆盖。该漏洞(CVE-2026-19585)已在 go-getter 1.8.10 和 go-getter/v2 2.2.5 版本中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HashiCorp | Shared library | 1.0.1 ~ 2.2.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet