HCSEC-2026-39 - Go-getter vulnerable to a privilege escalation issue in its archive decompression handling
Bulletin ID: HCSEC-2026-39 Affected Products / Versions: Go-getter up to 1.8.8 and 2.2.3; fixed in go-getter 1.8.9 and 2.2.4 Publication Date: September 15, 2026 Summary The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permiss…