If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 18 Sep 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Thu, 18 Sep 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned. | |
Title | Unexpected paths returned from LookPath in os/exec | |
References |
|

Status: PUBLISHED
Assigner: Go
Published:
Updated: 2025-09-18T20:42:38.389Z
Reserved: 2025-05-13T23:31:29.596Z
Link: CVE-2025-47906

Updated: 2025-09-18T20:42:34.381Z

Status : Received
Published: 2025-09-18T19:15:37.660
Modified: 2025-09-18T21:15:47.920
Link: CVE-2025-47906

No data.

No data.