CVE-2026-19585: Go-getter vulnerable to a path traversal in S3/GCS directory download handling
HashiCorp go-getter versions before 1.8.10 and go-getter/v2 versions before 2.2.5 are vulnerable to path traversal during S3 and GCS directory downloads, which may allow files to be written outside the requested destination. This vulnerability (CVE-2026-19585) is fixed in go-getter 1.8.10 and go-getter/v2 2.2.5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HashiCorp go-getterto a version that resolves this vulnerability.Fixed in 1.8.10 - Upgrade
Upgrade
HashiCorp go-getter/v2to a version that resolves this vulnerability.Fixed in 2.2.5
Event History
Frequently Asked Questions
Which deployments are affected?
Deployments using HashiCorp go-getter before version 1.8.10 or go-getter/v2 before version 2.2.5 are affected when performing directory downloads from S3 or GCS.
What does exploitation require?
The vulnerable operation is an S3 or GCS directory download. The attack requires conditions that allow path traversal through the downloaded content, potentially causing files to be written outside the requested destination.
Is integrity at risk?
Yes. The available severity vector indicates high integrity impact: successful exploitation may write files outside the intended download directory. No confidentiality or availability impact is indicated.
What version should be used to remediate the issue?
Upgrade go-getter to version 1.8.10 or later, or upgrade go-getter/v2 to version 2.2.5 or later.