CVE-2025-8959: HashiCorp go-getter Vulnerable to Arbitrary Read through Symlink Attack
Published Aug 15, 2025
·Updated
HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designated directory boundaries. This vulnerability, identified as CVE-2025-8959, is fixed in go-getter 1.7.9.
Affected Software
4 affected componentsFixes available
HashiCorp go-getter<1.7.9
go/github.com/hashicorp/go-getter<1.7.9
1.7.9
HashiCorp go-getter<1.7.9
IBM Concert Software<=1.0.0-2.1.0
Event History
Aug 15, 2025
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
Affected Software
Advisory Published
via GitHub·09:31 PM
Data Sourced
via GitHub·09:31 PM
DescriptionSeverityWeaknessAffected Software
Dec 22, 2025
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-8959?
CVE-2025-8959 has been identified as a high severity vulnerability due to its potential for unauthorized access.
2
How do I fix CVE-2025-8959?
To fix CVE-2025-8959, update the go-getter library to version 1.7.9 or later.
3
What type of attack does CVE-2025-8959 expose software to?
CVE-2025-8959 exposes software to symlink attacks that can lead to unauthorized read access.
4
Which versions of HashiCorp go-getter are affected by CVE-2025-8959?
Versions of HashiCorp go-getter prior to 1.7.9 are affected by CVE-2025-8959.
5
Who is the vendor associated with CVE-2025-8959?
The vendor associated with CVE-2025-8959 is HashiCorp.