CVE-2026-88922
MEDIUMDescription
The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permission bits. Where extraction is performed by a privileged user, this may allow a local actor to obtain the privileges of the extracting process. This vulnerability (CVE-2026-88922) is fixed in go-getter 1.8.9 and 2.2.4.
Is your site exposed to CVE-2026-88922?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2026-88922? +
How severe is CVE-2026-88922? +
How do I check if I'm vulnerable to CVE-2026-88922? +
Related Vulnerabilities
When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When …
A missing clean-up in the legacy Project Role Template Binding (PRTB) reconciler in Rancher versions 2.13.0 up to 2.13.7 and …
Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated user to access limited amount of documents via …
In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content …
SystemUI has an incorrect component protection setting, which allows access to specific information.
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of …