CVE-2025-8959 is a high-severity symlink attack vulnerability in HashiCorp's go-getter library (fixed in version 1.7.9) that allows unauthorized read access to files outside designated directories. With a CVSS score of 7.5 (High), this network-exploitable flaw could lead to significant information disclosure. While there is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, the vulnerability has garnered some community discussion. Its low EPSS score suggests a low probability of exploitation in the wild, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7.9CPE matchmatch criteria | cpe:2.3:a:hashicorp:go-getter:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.