If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.
Metrics
Affected Vendors & Products
References
History
Fri, 19 Sep 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Golang
Golang lookpath |
|
Vendors & Products |
Golang
Golang lookpath |
Thu, 18 Sep 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Thu, 18 Sep 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned. | |
Title | Unexpected paths returned from LookPath in os/exec | |
References |
|

Status: PUBLISHED
Assigner: Go
Published: 2025-09-18T18:41:11.847Z
Updated: 2025-09-18T20:42:38.389Z
Reserved: 2025-05-13T23:31:29.596Z
Link: CVE-2025-47906

Updated: 2025-09-18T20:42:34.381Z

Status : Awaiting Analysis
Published: 2025-09-18T19:15:37.660
Modified: 2025-09-19T16:00:27.847
Link: CVE-2025-47906

No data.