Intel

AIKIDO-2025-10563

github.com/hashicorp/go-getter is vulnerable to Insertion of Sensitive Information into Log File

Insertion of Sensitive Information into Log File Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Aug 18, 2025

9

Low Risk

This Affects:

GOgithub.com/hashicorp/go-getter
1.0.0 - 1.7.8
Fixed in 1.7.9
Are you affected? Scan for Free

TL;DR

Affected versions of this package may expose SSH keys in log files when multiple keys are included in the URL (e.g., ssh://git@github.com/hashicorp/go-getter-test-private.git?sshkey=secretkey&sshkey=secretkey). This flaw can lead to sensitive credential leakage.

Who does this affect?

You are affected if you are using a vulnerable version of the package.

Background info

github.com/hashicorp/go-getter is vulnerable to Insertion of Sensitive Information into Log File in versions 1.0.0 - 1.7.8.

How to fix this

Upgrade github.com/hashicorp/go-getter to a patch version.