go-getter 库在 1.8.8 及 2.2.3 版本之前均存在权限提升漏洞,具体表现为其归档解包处理机制存在缺陷:经过精心构造的归档包在解压时,可能导致生成的文件带有提升后的权限位。若解压操作由具有特权的用户执行,本地攻击者即可借此获得解压进程所拥有的权限。该漏洞(CVE-2026-88922)已在 go-getter 1.8.9 和 2.2.4 版本中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HashiCorp | Shared library | 1.0.1< 2.2.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HashiCorp | Shared library | 1.0.1 ~ 2.2.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet