216.73.216.226

CVE-2025-47906

· Published 18/09/2025 19:15 · Modified 19/09/2025 16:00

Labels: CVE-2025-47906 2025-09-18CVE-2025-47906[email protected]

Essential information

Published
18/09/2025 19:15
Modified
19/09/2025 16:00
Author
Creator
CVSS
6.5 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

CVSS metrics

Description

If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
golang / golang cpe:2.3:a:golang:golang:*:*:*:*:*:*:*:*

References