This vulnerability does not affect the go-getter/v2 branch and package.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1274 | HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect the go-getter/v2 branch and package. |
Github GHSA |
GHSA-q64h-39hv-4cf7 | HashiCorp go-getter Vulnerable to Argument Injection When Fetching Remote Default Git Branches |
Thu, 11 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:hashicorp:go-getter:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2024-08-01T20:20:01.607Z
Reserved: 2024-04-15T14:04:27.869Z
Link: CVE-2024-3817
Updated: 2024-08-01T20:20:01.607Z
Status : Analyzed
Published: 2024-04-17T20:15:08.383
Modified: 2026-06-17T07:45:10.573
Link: CVE-2024-3817
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:45:17Z
-
CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
EUVD
Github GHSA