Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-30195 | If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 04 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 26 Sep 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-440 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 19 Sep 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Golang
Golang lookpath |
|
| Vendors & Products |
Golang
Golang lookpath |
Thu, 18 Sep 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 18 Sep 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned. | |
| Title | Unexpected paths returned from LookPath in os/exec | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2025-11-04T21:10:54.782Z
Reserved: 2025-05-13T23:31:29.596Z
Link: CVE-2025-47906
Updated: 2025-11-04T21:10:54.782Z
Status : Awaiting Analysis
Published: 2025-09-18T19:15:37.660
Modified: 2025-11-04T22:16:16.207
Link: CVE-2025-47906
OpenCVE Enrichment
Updated: 2025-09-19T09:35:19Z
EUVD