CVE-2026-4660 is an arbitrary file read vulnerability in HashiCorp's go-getter library affecting versions up to and including v1.8.5. During certain git-based operations, a maliciously crafted URL can cause the library to read unintended files from the local filesystem. The issue is triggered in the context of git retrieval/download workflows that rely on go-getter URL processing. The vulnerability is fixed in go-getter v1.8.6. The go-getter/v2 branch and package are not affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a working PoC for CVE-2026-4660 affecting HashiCorp go-getter and downstream tools such as Terraform. It demonstrates an arbitrary local file read caused by passing an attacker-controlled Git `ref` beginning with `--pathspec-from-file=...`, which is later used in `git checkout` without a protective `--` separator. Git interprets the ref as an option, reads the specified local file line-by-line, and emits those lines in pathspec error messages, leaking file contents to terminal output and CI logs. Repository structure is small and purpose-built: `Dockerfile.gitserver` builds a malicious local HTTP git server hosting two bare repositories, including a legitimate-looking outer Terraform module (`terraform-aws-vpc.git`) whose nested module sources contain the malicious refs, and an inner module (`terraform-aws-vpc-internal.git`) used as the checkout target. `Dockerfile` builds the victim container with pinned vulnerable Terraform 1.14.8, fake AWS credentials, a fake SSH key, and the PoC runner script. `docker-compose.yml` orchestrates both containers and health-checks the git server. `poc.sh` is the main exploit entry point and demonstrates three stages: raw git checkout behavior, Terraform `init` triggering go-getter's `clone()` path, and a direct simulation of go-getter's `update()` path. Main exploit capabilities: (1) host attacker-controlled Git/Terraform modules over HTTP; (2) induce a victim to fetch a top-level module that silently references malicious nested modules; (3) leak arbitrary readable local files such as `/home/runner/.aws/credentials`, `/home/runner/.ssh/id_rsa`, and `/etc/passwd`; and (4) show behavioral differences between go-getter `clone()` and `update()` paths, specifically that `clone()` removes the destination on failure while `update()` leaves it behind. The exploit is operational rather than just illustrative because it fully automates environment setup and demonstrates real leakage through vulnerable tooling, but it uses hardcoded local infrastructure and sample files rather than a generalized payload framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.