Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-88922— Go-getter vulnerable to a privilege escalation issue in its archive decompression handling

Quick assessment

Affected
HashiCorp Shared library
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

go-getter 库在 1.8.8 及 2.2.3 版本之前均存在权限提升漏洞,具体表现为其归档解包处理机制存在缺陷:经过精心构造的归档包在解压时,可能导致生成的文件带有提升后的权限位。若解压操作由具有特权的用户执行,本地攻击者即可借此获得解压进程所拥有的权限。该漏洞(CVE-2026-88922)已在 go-getter 1.8.9 和 2.2.4 版本中修复。

CVSS 6.7 · Medium EPSS 0.09% · P0

Affected Version Matrix 1

VendorProduct Version RangeStatus
HashiCorp Shared library 1.0.1< 2.2.4 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-88922

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Go-getter vulnerable to a privilege escalation issue in its archive decompression handling
Source: CVE Program / CVE List V5
Vulnerability Description
The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permission bits. Where extraction is performed by a privileged user, this may allow a local actor to obtain the privileges of the extracting process. This vulnerability (CVE-2026-88922) is fixed in go-getter 1.8.9 and 2.2.4.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
权限预留不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
HashiCorp Shared library 1.0.1 ~ 2.2.4 -

II. Public POCs for CVE-2026-88922

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-88922

登录查看更多情报信息。

Vendor Advisories for CVE-2026-88922 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-88922

No comments yet


Leave a comment