Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-30195 | If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 05 Nov 2025 07:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 26 Sep 2025 21:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-440 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 19 Sep 2025 18:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Golang
Golang lookpath |
|
| Vendors & Products |
Golang
Golang lookpath |
Fri, 19 Sep 2025 06:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 19 Sep 2025 04:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned. | |
| Title | Unexpected paths returned from LookPath in os/exec | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2025-11-04T21:10:54.782Z
Reserved: 2025-05-13T23:31:29.596Z
Link: CVE-2025-47906
Updated: 2025-11-04T21:10:54.782Z
Status : Awaiting Analysis
Published: 2025-09-18T19:15:37.660
Modified: 2025-11-04T22:16:16.207
Link: CVE-2025-47906
OpenCVE Enrichment
Updated: 2025-09-19T18:35:19Z
EUVD