Home

Description

If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.

PUBLISHED Reserved 2025-05-13 | Published 2025-09-18 | Updated 2025-11-04 | Assigner Go

Problem types

CWE-115: Misinterpretation of Input

Product status

Default status
unaffected

Any version before 1.23.12
affected

1.24.0 (semver) before 1.24.6
affected

References

www.openwall.com/lists/oss-security/2025/08/06/1

go.dev/cl/691775

go.dev/issue/74466

groups.google.com/g/golang-announce/c/x5MKroML2yM

pkg.go.dev/vuln/GO-2025-3956

cve.org (CVE-2025-47906)

nvd.nist.gov (CVE-2025-47906)

Download JSON