HCSEC-2026-44 - Go-getter vulnerable to a path traversal in S3/GCS directory download handling

Bulletin ID: HCSEC-2026-44

Affected Products / Versions: Go-getter up to 1.8.9 and 2.2.4; fixed in go-getter 1.8.10 and 2.2.5

Publication Date: October 8, 2026

Summary

HashiCorp go-getter versions before 1.8.10 and go-getter/v2 versions before 2.2.5 are vulnerable to path traversal during S3 and GCS directory downloads, which may allow files to be written outside the requested destination. This vulnerability (CVE-2026-19585) is fixed in go-getter 1.8.10 and go-getter/v2 2.2.5.

Background

Go-getter is a Go library for downloading files and directories from sources including Amazon S3 and Google Cloud Storage. In directory mode, it downloads objects under a requested prefix into a local destination directory.

Details

S3 and GCS directory downloads did not ensure that each listed object’s destination remained within the requested directory. An attacker who can influence an object name in a bucket that an application retrieves in directory mode may cause files to be written outside that destination, subject to the downloader’s filesystem permissions. Single-object downloads are not affected.

Remediation

Customers should evaluate the risk associated with this issue and consider upgrading to go-getter 1.8.10 or go-getter/v2 2.2.5.

Acknowledgement

This issue was reported to HashiCorp by Kris Kennaway.

We deeply appreciate any effort to coordinate disclosure of security vulnerabilities. For information about security at HashiCorp and the reporting of security vulnerabilities, please see https://hashicorp.com/security.