- Description
- If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.
- Source
- security@golang.org
- NVD status
- Analyzed
- Products
- go
CVSS 3.1
- Type
- Secondary
- Base score
- 6.5
- Impact score
- 2.5
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
- Severity
- MEDIUM
- Hype score
- Not currently trending
๐จ CRITICAL UPDATE for #GoLang devs using Google Wire for DI. CVE-2025-47906 allows command execution hijack via os/exec.LookPath. #Fedora 42 patch is live (v0.6.0-14). Read more: ๐ https://t.co/OxekHJJTov #Security https://t.co/Vgzr4AryTa
@Cezar_H_Linux
1 Jan 2026
92 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
Just published: An in-depth analysis of the critical #Fedora Delve debugger vulnerability (FEDORA-2025-3591ae9dd3 / CVE-2025-47906). Read more: ๐ https://t.co/5RWPjULTJJ #Security https://t.co/S6U8MHQ3qE
@Cezar_H_Linux
1 Jan 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
A security vulnerability in delve (go-toolset:rhel8) is addressed by CVE-2025-47906. Update to version 0:1.7.2-1 or later to mitigate. https://t.co/plsqUO67eW
@pulsepatchio
23 Dec 2025
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Urgent: CVE-2025-47906 patched for #vgrep on #Fedora42. Impact: Critical. Can lead to arbitrary code execution. Read more: ๐ https://t.co/kfPxMJZtjE #Security https://t.co/vTSjcJSvur
@Cezar_H_Linux
1 Nov 2025
35 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
New security advisory for the #openSUSE community. The govulncheck-vulndb package has been updated to version 0.0.20250918T182144-1.1 to address two moderate-severity vulnerabilities (CVE-2025-47906 and CVE-2025-5187). Read more: ๐ https://t.co/zp5wXmNhTR #Security https://t.c
@Cezar_H_Linux
21 Sept 2025
42 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
URGENT: Patch Go 1.24 now! CVE-2025-47906 (CVSS 4.0) & CVE-2025-47907 (CVSS 7.0) impact 35+ SUSE distros (Leap/SLES/SAP/HPC). Exploits allow path hijacking & DB corruption. Read more:๐ https://t.co/7SlwnaLWqA #Security #SUSE https://t.co/4a7foJYyrP
@Cezar_H_Linux
12 Aug 2025
57 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
URGENT: @openSUSE Tumbleweed patches 2x Golang vulns (CVE-2025-47906/47907). Read more:๐https://t.co/bbjTRTCU56 #Security https://t.co/CkguvznurX
@Cezar_H_Linux
10 Aug 2025
24 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
๐ Go 1.24.6 and 1.23.12 are released! ๐ Security: Includes security fixes for os/exec (CVE-2025-47906) and database/sql (CVE-2025-47907). ๐ข Announcement: https://t.co/o2LJKjXYvP โฌ๏ธ Download: https://t.co/ffHEmehO2d #golang https://t.co/4MF9a7DSL7
@golang
6 Aug 2025
17624 Impressions
84 Retweets
350 Likes
19 Bookmarks
0 Replies
2 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*",
"matchCriteriaId": "6B868FEB-2BCB-4816-B575-BEF1ADD15C5F",
"versionEndExcluding": "1.23.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*",
"matchCriteriaId": "21442DAA-1345-47FB-8DA6-2589ABB8CB08",
"versionEndExcluding": "1.24.6",
"versionStartIncluding": "1.24.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]