CVE-2025-47906

If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.
References
Link Resource
https://go.dev/cl/691775 Patch
https://go.dev/issue/74466 Exploit Issue Tracking Third Party Advisory
https://groups.google.com/g/golang-announce/c/x5MKroML2yM Mailing List Release Notes
https://pkg.go.dev/vuln/GO-2025-3956 Vendor Advisory
http://www.openwall.com/lists/oss-security/2025/08/06/1 Mailing List Issue Tracking
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-09-18 19:15

Updated : 2026-01-27 19:56


NVD link : CVE-2025-47906

Mitre link : CVE-2025-47906

CVE.ORG link : CVE-2025-47906


JSON object : View

Products Affected

golang

  • go