If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.
References
| Link | Resource |
|---|---|
| https://go.dev/cl/691775 | Patch |
| https://go.dev/issue/74466 | Exploit Issue Tracking Third Party Advisory |
| https://groups.google.com/g/golang-announce/c/x5MKroML2yM | Mailing List Release Notes |
| https://pkg.go.dev/vuln/GO-2025-3956 | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2025/08/06/1 | Mailing List Issue Tracking |
Configurations
History
No history.
Information
Published : 2025-09-18 19:15
Updated : 2026-01-27 19:56
NVD link : CVE-2025-47906
Mitre link : CVE-2025-47906
CVE.ORG link : CVE-2025-47906
JSON object : View
Products Affected
golang
- go
CWE
