CVE-2025-8959Link Following in Shared Library

CWE-59Link Following8 documents6 sources
Severity
7.5HIGHNVD
EPSS
0.0%
top 92.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 15
Latest updateAug 29

Description

HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designated directory boundaries. This vulnerability, identified as CVE-2025-8959, is fixed in go-getter 1.7.9.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

🔴Vulnerability Details

5
OSV
HashiCorp go-getter Vulnerable to Symlink Attacks in github.com/hashicorp/go-getter2025-08-29
OSV
CVE-2025-8959: HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designated2025-08-15
CVEList
HashiCorp go-getter Vulnerable to Arbitrary Read through Symlink Attack2025-08-15
OSV
HashiCorp go-getter Vulnerable to Symlink Attacks2025-08-15
GHSA
HashiCorp go-getter Vulnerable to Symlink Attacks2025-08-15

📋Vendor Advisories

2
Red Hat
github.com/hashicorp/go-getter: HashiCorp go-getter Arbitrary File Read2025-08-15
Debian
CVE-2025-8959: golang-github-hashicorp-go-getter - HashiCorp's go-getter library subdirectory download feature is vulnerable to sym...2025
CVE-2025-8959 — Link Following in Shared Library | cvebase