CVE-2025-47906

I

f the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.

References
Link Resource
https://go.dev/cl/691775 Patch
https://go.dev/issue/74466 Exploit Issue Tracking Third Party Advisory
https://groups.google.com/g/golang-announce/c/x5MKroML2yM Mailing List Release Notes
https://pkg.go.dev/vuln/GO-2025-3956 Vendor Advisory
http://www.openwall.com/lists/oss-security/2025/08/06/1 Mailing List Issue Tracking
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*

History

27 Jan 2026, 19:56

Type Values Removed Values Added
CWE NVD-CWE-Other
CPE cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
References () https://go.dev/cl/691775 - () https://go.dev/cl/691775 - Patch
References () https://go.dev/issue/74466 - () https://go.dev/issue/74466 - Exploit, Issue Tracking, Third Party Advisory
References () https://groups.google.com/g/golang-announce/c/x5MKroML2yM - () https://groups.google.com/g/golang-announce/c/x5MKroML2yM - Mailing List, Release Notes
References () https://pkg.go.dev/vuln/GO-2025-3956 - () https://pkg.go.dev/vuln/GO-2025-3956 - Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2025/08/06/1 - () http://www.openwall.com/lists/oss-security/2025/08/06/1 - Mailing List, Issue Tracking
First Time Golang go
Golang

04 Nov 2025, 22:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/08/06/1 -

19 Sep 2025, 16:00

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-18 19:15

Updated : 2026-01-27 19:56


NVD link : CVE-2025-47906

Mitre link : CVE-2025-47906

CVE.ORG link : CVE-2025-47906


JSON object : View

Products Affected