CyberRota Analysis
AI-GeneratedThe vulnerability affects Packer versions up to 1.15.4, specifically in its third-party plugin installer, which can allow for unintended file system modifications and potentially lead to code execution if a user installs a plugin from a malicious source. Organizations using Packer for infrastructure automation should prioritize updating to version 1.16.0 to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow unintended file system modification and could lead to code execution. A user who installs a plugin from a malicious or compromised source may be affected. This vulnerability (CVE-2026-19589) is fixed in Packer 1.16.0.