If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.
References
| Link | Resource |
|---|---|
| https://go.dev/cl/691775 | Patch |
| https://go.dev/issue/74466 | Exploit Issue Tracking Third Party Advisory |
| https://groups.google.com/g/golang-announce/c/x5MKroML2yM | Mailing List Release Notes |
| https://pkg.go.dev/vuln/GO-2025-3956 | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2025/08/06/1 | Mailing List Issue Tracking |
Configurations
History
27 Jan 2026, 19:56
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Golang go
Golang |
|
| CPE | cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* | |
| References | () https://go.dev/cl/691775 - Patch | |
| References | () https://go.dev/issue/74466 - Exploit, Issue Tracking, Third Party Advisory | |
| References | () https://groups.google.com/g/golang-announce/c/x5MKroML2yM - Mailing List, Release Notes | |
| References | () https://pkg.go.dev/vuln/GO-2025-3956 - Vendor Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2025/08/06/1 - Mailing List, Issue Tracking | |
| CWE | NVD-CWE-Other |
04 Nov 2025, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
18 Sep 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
18 Sep 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-09-18 19:15
Updated : 2026-01-27 19:56
NVD link : CVE-2025-47906
Mitre link : CVE-2025-47906
CVE.ORG link : CVE-2025-47906
JSON object : View
Products Affected
golang
- go
CWE
