CVE-2024-6257

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
25/06/2024
Last modified:
11/12/2025

Description

HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hashicorp:go-getter:*:*:*:*:*:*:*:* 1.7.5 (excluding)