github.com/hashicorp/go-getter
Package for downloading things from a string URL using a variety of protocols.
Activity
- Latest release
- 1w ago
- Total releases
- 22
- Cadence
- ~31 days
- Last 12 months
- 8
Reach
- Stars
- 1.8k
Details
- First release
- Jun 13, 2022
| Version | Released | |
|---|---|---|
v1.8.9
patch
|
v1.8.9
patch
Dependencies (17)
+ 9 more |
|
v1.8.8
patch
|
v1.8.8
patch
Dependencies (17)
+ 9 more |
|
v1.8.7
patch
|
v1.8.7
patch
Dependencies (17)
+ 9 more |
|
v1.8.6
patch
|
v1.8.6
patch
Dependencies (17)
+ 9 more |
|
v1.8.5
patch
1 CVE
CVE-2026-4660
GO-2026-5058
GHSA-92mm-2pjq-r785
Jun 22, 2026
HashiCorp's go-getter library may allow arbitrary file reads in github.com/hashicorp/go-getter HashiCorp's go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package. Fixed in
1.8.6
References Updated Jul 02, 2026 · Source: OSV.dev |
v1.8.5
patch
Dependencies (17)
+ 9 more |
|
v1.8.4
patch
1 CVE
CVE-2026-4660
GO-2026-5058
GHSA-92mm-2pjq-r785
Jun 22, 2026
HashiCorp's go-getter library may allow arbitrary file reads in github.com/hashicorp/go-getter HashiCorp's go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package. Fixed in
1.8.6
References Updated Jul 02, 2026 · Source: OSV.dev |
v1.8.4
patch
Dependencies (17)
+ 9 more |
|
v1.8.3
patch
1 CVE
CVE-2026-4660
GO-2026-5058
GHSA-92mm-2pjq-r785
Jun 22, 2026
HashiCorp's go-getter library may allow arbitrary file reads in github.com/hashicorp/go-getter HashiCorp's go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package. Fixed in
1.8.6
References Updated Jul 02, 2026 · Source: OSV.dev |
v1.8.3
patch
Dependencies (17)
+ 9 more |
|
v1.8.2
patch
1 CVE
CVE-2026-4660
GO-2026-5058
GHSA-92mm-2pjq-r785
Jun 22, 2026
HashiCorp's go-getter library may allow arbitrary file reads in github.com/hashicorp/go-getter HashiCorp's go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package. Fixed in
1.8.6
References Updated Jul 02, 2026 · Source: OSV.dev |
v1.8.2
patch
Dependencies (17)
+ 9 more |
|
v1.8.1
patch
1 CVE
CVE-2026-4660
GO-2026-5058
GHSA-92mm-2pjq-r785
Jun 22, 2026
HashiCorp's go-getter library may allow arbitrary file reads in github.com/hashicorp/go-getter HashiCorp's go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package. Fixed in
1.8.6
References Updated Jul 02, 2026 · Source: OSV.dev |
v1.8.1
patch
Dependencies (18)
+ 10 more |
|
v1.8.0
minor
1 CVE
CVE-2026-4660
GO-2026-5058
GHSA-92mm-2pjq-r785
Jun 22, 2026
HashiCorp's go-getter library may allow arbitrary file reads in github.com/hashicorp/go-getter HashiCorp's go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package. Fixed in
1.8.6
References Updated Jul 02, 2026 · Source: OSV.dev |
v1.8.0
minor
Dependencies (17)
+ 9 more |
|
v1.7.10
patch
1 CVE
CVE-2026-4660
GO-2026-5058
GHSA-92mm-2pjq-r785
Jun 22, 2026
HashiCorp's go-getter library may allow arbitrary file reads in github.com/hashicorp/go-getter HashiCorp's go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package. Fixed in
1.8.6
References Updated Jul 02, 2026 · Source: OSV.dev |
v1.7.10
patch
Dependencies (17)
+ 9 more |
|
v1.7.9
patch
1 CVE
CVE-2026-4660
GO-2026-5058
GHSA-92mm-2pjq-r785
Jun 22, 2026
HashiCorp's go-getter library may allow arbitrary file reads in github.com/hashicorp/go-getter HashiCorp's go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package. Fixed in
1.8.6
References Updated Jul 02, 2026 · Source: OSV.dev |
v1.7.9
patch
Dependencies (12)
+ 4 more |
|
v1.7.8
patch
2 CVEs
CVE-2026-4660
GO-2026-5058
GHSA-92mm-2pjq-r785
Jun 22, 2026
HashiCorp's go-getter library may allow arbitrary file reads in github.com/hashicorp/go-getter HashiCorp's go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package. Fixed in
1.8.6
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-8959
GO-2025-3892
GHSA-wjrx-6529-hcj3
Aug 29, 2025
HashiCorp go-getter Vulnerable to Symlink Attacks in github.com/hashicorp/go-getter HashiCorp go-getter Vulnerable to Symlink Attacks in github.com/hashicorp/go-getter Fixed in
1.7.9
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.7.8
patch
Dependencies (13)
+ 5 more |
|
v1.7.7
patch
2 CVEs
CVE-2026-4660
GO-2026-5058
GHSA-92mm-2pjq-r785
Jun 22, 2026
HashiCorp's go-getter library may allow arbitrary file reads in github.com/hashicorp/go-getter HashiCorp's go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package. Fixed in
1.8.6
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-8959
GO-2025-3892
GHSA-wjrx-6529-hcj3
Aug 29, 2025
HashiCorp go-getter Vulnerable to Symlink Attacks in github.com/hashicorp/go-getter HashiCorp go-getter Vulnerable to Symlink Attacks in github.com/hashicorp/go-getter Fixed in
1.7.9
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.7.7
patch
Dependencies (13)
+ 5 more |
|
v1.7.6
patch
2 CVEs
CVE-2026-4660
GO-2026-5058
GHSA-92mm-2pjq-r785
Jun 22, 2026
HashiCorp's go-getter library may allow arbitrary file reads in github.com/hashicorp/go-getter HashiCorp's go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package. Fixed in
1.8.6
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-8959
GO-2025-3892
GHSA-wjrx-6529-hcj3
Aug 29, 2025
HashiCorp go-getter Vulnerable to Symlink Attacks in github.com/hashicorp/go-getter HashiCorp go-getter Vulnerable to Symlink Attacks in github.com/hashicorp/go-getter Fixed in
1.7.9
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.7.6
patch
Dependencies (13)
+ 5 more |
|
v1.7.5
patch
2 CVEs
CVE-2026-4660
GO-2026-5058
GHSA-92mm-2pjq-r785
Jun 22, 2026
HashiCorp's go-getter library may allow arbitrary file reads in github.com/hashicorp/go-getter HashiCorp's go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package. Fixed in
1.8.6
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-8959
GO-2025-3892
GHSA-wjrx-6529-hcj3
Aug 29, 2025
HashiCorp go-getter Vulnerable to Symlink Attacks in github.com/hashicorp/go-getter HashiCorp go-getter Vulnerable to Symlink Attacks in github.com/hashicorp/go-getter Fixed in
1.7.9
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.7.5
patch
Dependencies (13)
+ 5 more |
|
v1.7.4
patch
3 CVEs
CVE-2026-4660
GO-2026-5058
GHSA-92mm-2pjq-r785
Jun 22, 2026
HashiCorp's go-getter library may allow arbitrary file reads in github.com/hashicorp/go-getter HashiCorp's go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package. Fixed in
1.8.6
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-8959
GO-2025-3892
GHSA-wjrx-6529-hcj3
Aug 29, 2025
HashiCorp go-getter Vulnerable to Symlink Attacks in github.com/hashicorp/go-getter HashiCorp go-getter Vulnerable to Symlink Attacks in github.com/hashicorp/go-getter Fixed in
1.7.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-6257
GO-2024-2948
GHSA-xfhp-jf8p-mh5w
Jun 28, 2024
Code Execution on Git update in github.com/hashicorp/go-getter A crafted request can execute Git update on an existing maliciously modified Git Configuration. This can potentially lead to arbitrary code execution. When performing a Git operation, the library will try to clone the given repository to a specified destination. Cloning initializes a git config in the provided destination. An attacker may alter the Git config after the cloning step to set an arbitrary Git configuration to achieve code execution. Fixed in
1.7.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.7.4
patch
Dependencies (13)
+ 5 more |
|
v1.7.3
patch
4 CVEs
CVE-2026-4660
GO-2026-5058
GHSA-92mm-2pjq-r785
Jun 22, 2026
HashiCorp's go-getter library may allow arbitrary file reads in github.com/hashicorp/go-getter HashiCorp's go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package. Fixed in
1.8.6
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-8959
GO-2025-3892
GHSA-wjrx-6529-hcj3
Aug 29, 2025
HashiCorp go-getter Vulnerable to Symlink Attacks in github.com/hashicorp/go-getter HashiCorp go-getter Vulnerable to Symlink Attacks in github.com/hashicorp/go-getter Fixed in
1.7.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-6257
GO-2024-2948
GHSA-xfhp-jf8p-mh5w
Jun 28, 2024
Code Execution on Git update in github.com/hashicorp/go-getter A crafted request can execute Git update on an existing maliciously modified Git Configuration. This can potentially lead to arbitrary code execution. When performing a Git operation, the library will try to clone the given repository to a specified destination. Cloning initializes a git config in the provided destination. An attacker may alter the Git config after the cloning step to set an arbitrary Git configuration to achieve code execution. Fixed in
1.7.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-3817
GO-2024-2800
GHSA-q64h-39hv-4cf7
May 10, 2024
Argument injection when fetching remote default Git branches in github.com/hashicorp/go-getter When go-getter is performing a Git operation, go-getter will try to clone the given repository. If a Git reference is not passed along with the Git url, go-getter will then try to check the remote repository's HEAD reference of its default branch by passing arguments to the Git binary on the host it is executing on. An attacker may format a Git URL in order to inject additional Git arguments to the Git call. Fixed in
1.7.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.7.3
patch
Dependencies (13)
+ 5 more |
|
v1.7.2
patch
4 CVEs
CVE-2026-4660
GO-2026-5058
GHSA-92mm-2pjq-r785
Jun 22, 2026
HashiCorp's go-getter library may allow arbitrary file reads in github.com/hashicorp/go-getter HashiCorp's go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package. Fixed in
1.8.6
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-8959
GO-2025-3892
GHSA-wjrx-6529-hcj3
Aug 29, 2025
HashiCorp go-getter Vulnerable to Symlink Attacks in github.com/hashicorp/go-getter HashiCorp go-getter Vulnerable to Symlink Attacks in github.com/hashicorp/go-getter Fixed in
1.7.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-6257
GO-2024-2948
GHSA-xfhp-jf8p-mh5w
Jun 28, 2024
Code Execution on Git update in github.com/hashicorp/go-getter A crafted request can execute Git update on an existing maliciously modified Git Configuration. This can potentially lead to arbitrary code execution. When performing a Git operation, the library will try to clone the given repository to a specified destination. Cloning initializes a git config in the provided destination. An attacker may alter the Git config after the cloning step to set an arbitrary Git configuration to achieve code execution. Fixed in
1.7.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-3817
GO-2024-2800
GHSA-q64h-39hv-4cf7
May 10, 2024
Argument injection when fetching remote default Git branches in github.com/hashicorp/go-getter When go-getter is performing a Git operation, go-getter will try to clone the given repository. If a Git reference is not passed along with the Git url, go-getter will then try to check the remote repository's HEAD reference of its default branch by passing arguments to the Git binary on the host it is executing on. An attacker may format a Git URL in order to inject additional Git arguments to the Git call. Fixed in
1.7.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.7.2
patch
Dependencies (13)
+ 5 more |
|
v1.7.1
patch
4 CVEs
CVE-2026-4660
GO-2026-5058
GHSA-92mm-2pjq-r785
Jun 22, 2026
HashiCorp's go-getter library may allow arbitrary file reads in github.com/hashicorp/go-getter HashiCorp's go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package. Fixed in
1.8.6
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-8959
GO-2025-3892
GHSA-wjrx-6529-hcj3
Aug 29, 2025
HashiCorp go-getter Vulnerable to Symlink Attacks in github.com/hashicorp/go-getter HashiCorp go-getter Vulnerable to Symlink Attacks in github.com/hashicorp/go-getter Fixed in
1.7.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-6257
GO-2024-2948
GHSA-xfhp-jf8p-mh5w
Jun 28, 2024
Code Execution on Git update in github.com/hashicorp/go-getter A crafted request can execute Git update on an existing maliciously modified Git Configuration. This can potentially lead to arbitrary code execution. When performing a Git operation, the library will try to clone the given repository to a specified destination. Cloning initializes a git config in the provided destination. An attacker may alter the Git config after the cloning step to set an arbitrary Git configuration to achieve code execution. Fixed in
1.7.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-3817
GO-2024-2800
GHSA-q64h-39hv-4cf7
May 10, 2024
Argument injection when fetching remote default Git branches in github.com/hashicorp/go-getter When go-getter is performing a Git operation, go-getter will try to clone the given repository. If a Git reference is not passed along with the Git url, go-getter will then try to check the remote repository's HEAD reference of its default branch by passing arguments to the Git binary on the host it is executing on. An attacker may format a Git URL in order to inject additional Git arguments to the Git call. Fixed in
1.7.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.7.1
patch
Dependencies (13)
+ 5 more |
|
v1.7.0
minor
4 CVEs
CVE-2026-4660
GO-2026-5058
GHSA-92mm-2pjq-r785
Jun 22, 2026
HashiCorp's go-getter library may allow arbitrary file reads in github.com/hashicorp/go-getter HashiCorp's go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package. Fixed in
1.8.6
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-8959
GO-2025-3892
GHSA-wjrx-6529-hcj3
Aug 29, 2025
HashiCorp go-getter Vulnerable to Symlink Attacks in github.com/hashicorp/go-getter HashiCorp go-getter Vulnerable to Symlink Attacks in github.com/hashicorp/go-getter Fixed in
1.7.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-6257
GO-2024-2948
GHSA-xfhp-jf8p-mh5w
Jun 28, 2024
Code Execution on Git update in github.com/hashicorp/go-getter A crafted request can execute Git update on an existing maliciously modified Git Configuration. This can potentially lead to arbitrary code execution. When performing a Git operation, the library will try to clone the given repository to a specified destination. Cloning initializes a git config in the provided destination. An attacker may alter the Git config after the cloning step to set an arbitrary Git configuration to achieve code execution. Fixed in
1.7.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-3817
GO-2024-2800
GHSA-q64h-39hv-4cf7
May 10, 2024
Argument injection when fetching remote default Git branches in github.com/hashicorp/go-getter When go-getter is performing a Git operation, go-getter will try to clone the given repository. If a Git reference is not passed along with the Git url, go-getter will then try to check the remote repository's HEAD reference of its default branch by passing arguments to the Git binary on the host it is executing on. An attacker may format a Git URL in order to inject additional Git arguments to the Git call. Fixed in
1.7.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.7.0
minor
Dependencies (13)
+ 5 more |
|
v1.6.2
initial
5 CVEs
CVE-2026-4660
GO-2026-5058
GHSA-92mm-2pjq-r785
Jun 22, 2026
HashiCorp's go-getter library may allow arbitrary file reads in github.com/hashicorp/go-getter HashiCorp's go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package. Fixed in
1.8.6
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-8959
GO-2025-3892
GHSA-wjrx-6529-hcj3
Aug 29, 2025
HashiCorp go-getter Vulnerable to Symlink Attacks in github.com/hashicorp/go-getter HashiCorp go-getter Vulnerable to Symlink Attacks in github.com/hashicorp/go-getter Fixed in
1.7.9
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-6257
GO-2024-2948
GHSA-xfhp-jf8p-mh5w
Jun 28, 2024
Code Execution on Git update in github.com/hashicorp/go-getter A crafted request can execute Git update on an existing maliciously modified Git Configuration. This can potentially lead to arbitrary code execution. When performing a Git operation, the library will try to clone the given repository to a specified destination. Cloning initializes a git config in the provided destination. An attacker may alter the Git config after the cloning step to set an arbitrary Git configuration to achieve code execution. Fixed in
1.7.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-3817
GO-2024-2800
GHSA-q64h-39hv-4cf7
May 10, 2024
Argument injection when fetching remote default Git branches in github.com/hashicorp/go-getter When go-getter is performing a Git operation, go-getter will try to clone the given repository. If a Git reference is not passed along with the Git url, go-getter will then try to check the remote repository's HEAD reference of its default branch by passing arguments to the Git binary on the host it is executing on. An attacker may format a Git URL in order to inject additional Git arguments to the Git call. Fixed in
1.7.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0475
GO-2023-1578
GHSA-jpxj-2jvg-6jv9
Feb 17, 2023
Denial of service in github.com/hashicorp/go-getter/v2 HashiCorp go-getter is vulnerable to decompression bombs. This can lead to excessive memory consumption and denial-of-service attacks. Fixed in
1.7.0
References Updated May 20, 2024 · Source: OSV.dev |
v1.6.2
initial
Dependencies (13)
+ 5 more |