If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.
References
| Link | Resource |
|---|---|
| https://go.dev/cl/691775 | Patch |
| https://go.dev/issue/74466 | Exploit Issue Tracking Third Party Advisory |
| https://groups.google.com/g/golang-announce/c/x5MKroML2yM | Mailing List Release Notes |
| https://pkg.go.dev/vuln/GO-2025-3956 | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2025/08/06/1 | Issue Tracking Mailing List |
Configurations
History
17 Jun 2026, 09:28
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://www.openwall.com/lists/oss-security/2025/08/06/1 - Issue Tracking, Mailing List |
27 Jan 2026, 19:56
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Golang go
Golang |
|
| CPE | cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* | |
| References | () https://go.dev/cl/691775 - Patch | |
| References | () https://go.dev/issue/74466 - Exploit, Issue Tracking, Third Party Advisory | |
| References | () https://groups.google.com/g/golang-announce/c/x5MKroML2yM - Mailing List, Release Notes | |
| References | () https://pkg.go.dev/vuln/GO-2025-3956 - Vendor Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2025/08/06/1 - Mailing List, Issue Tracking | |
| CWE | NVD-CWE-Other |
04 Nov 2025, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
18 Sep 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
18 Sep 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-09-18 19:15
Updated : 2026-06-17 09:28
NVD link : CVE-2025-47906
Mitre link : CVE-2025-47906
CVE.ORG link : CVE-2025-47906
JSON object : View
Products Affected
golang
- go
CWE
