CVE-2025-47906

If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.
References
Link Resource
https://go.dev/cl/691775 Patch
https://go.dev/issue/74466 Exploit Issue Tracking Third Party Advisory
https://groups.google.com/g/golang-announce/c/x5MKroML2yM Mailing List Release Notes
https://pkg.go.dev/vuln/GO-2025-3956 Vendor Advisory
http://www.openwall.com/lists/oss-security/2025/08/06/1 Mailing List Issue Tracking
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*

History

27 Jan 2026, 19:56

Type Values Removed Values Added
First Time Golang go
Golang
CPE cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
References () https://go.dev/cl/691775 - () https://go.dev/cl/691775 - Patch
References () https://go.dev/issue/74466 - () https://go.dev/issue/74466 - Exploit, Issue Tracking, Third Party Advisory
References () https://groups.google.com/g/golang-announce/c/x5MKroML2yM - () https://groups.google.com/g/golang-announce/c/x5MKroML2yM - Mailing List, Release Notes
References () https://pkg.go.dev/vuln/GO-2025-3956 - () https://pkg.go.dev/vuln/GO-2025-3956 - Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2025/08/06/1 - () http://www.openwall.com/lists/oss-security/2025/08/06/1 - Mailing List, Issue Tracking
CWE NVD-CWE-Other

04 Nov 2025, 22:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/08/06/1 -

18 Sep 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

18 Sep 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-18 19:15

Updated : 2026-01-27 19:56


NVD link : CVE-2025-47906

Mitre link : CVE-2025-47906

CVE.ORG link : CVE-2025-47906


JSON object : View

Products Affected

golang

  • go