Untriaged
Permalink
CVE-2026-4660
7.5 HIGH
- CVSS version: 3.1
- Attack vector (AV):
- Attack complexity (AC):
- Privileges required (PR):
- User interaction (UI):
- Scope (S):
- Confidentiality impact (C):
- Integrity impact (I):
- Availability impact (A):
Go-getter may allow to arbitrary filesystem reads through git operations
HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This vulnerability, CVE-2026-4660, is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package.
Affected products
Tooling
- <1.8.6
Matching in nixpkgs
pkgs.igvm-tooling
IGVM Image Generator
pkgs.xml-tooling-c
Low-level library that provides a high level interface to XML processing for OpenSAML 2
pkgs.tooling-language-server
Language server for tools and package managers
pkgs.elmPackages.elm-language-server
Language server implementation for Elm
Package maintainers
-
@turboMaCk Marek Fajkus <marek.faj@gmail.com>
-
@katexochen Paul Meyer <katexochen0@gmail.com>
-
@malt3 Malte Poll
-
@niklaskorz Niklas Korz <nixpkgs@korz.dev>
-
@mcwitt Matt Wittmann <mcwitt@gmail.com>
-
@Sigmanificient Yohann Boniface <sigmanificient@gmail.com>