CVE-2026-19589: Packer vulnerable to arbitrary file write via crafted plugin archive during installation
Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow unintended file system modification and could lead to code execution. A user who installs a plugin from a malicious or compromised source may be affected. This vulnerability (CVE-2026-19589) is fixed in Packer 1.16.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Packerto a version that resolves this vulnerability.Fixed in 1.16.0Patch CVE-2026-19589
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19589?
The severity of CVE-2026-19589 is classified as high with a CVSS score of 7.1.
How do I fix CVE-2026-19589?
To fix CVE-2026-19589, update Packer to the latest version beyond 1.15.4 where this vulnerability is addressed.
What is CVE-2026-19589?
CVE-2026-19589 is a vulnerability in Packer that allows arbitrary file writes via malicious plugin archives during installation.
Who is affected by CVE-2026-19589?
Users who install plugins from malicious or compromised sources are at risk from CVE-2026-19589.
What could be the impact of exploiting CVE-2026-19589?
Exploiting CVE-2026-19589 could lead to unintended file system modifications and potential code execution.