PT-2026-92472 · Go-Getter · Go-Getter

CVE-2026-88922

·

Published

2026-09-15

·

Updated

2026-10-05

CVSS v3.1

6.7

Medium

VectorAV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions go-getter versions prior to 1.8.9 go-getter versions prior to 2.2.4
Description A privilege escalation issue exists in the archive decompression handling. A crafted archive can cause extracted files to be created with elevated permission bits. If the extraction is performed by a privileged user, a local actor may obtain the privileges of the extracting process.
Recommendations Update to version 1.8.9. Update to version 2.2.4.

Exploit

Fix

LPE

Improper Preservation of Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-103254
CVE-2026-88922
RHSA-2026:68251
RHSA-2026:68255
RHSA-2026:68259
RHSA-2026:68261
SUSE-SU-2026:4444-1

Affected Products

Go-Getter