PT-2025-46010 · Julia · Registrator
Published
2025-10-08
·
Updated
2025-10-08
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Impact
If the clone URL returned by GitHub is malicious (or can be injected using upstream vulnerabilities), an argument injection is possible in the
gettreesha() function. This can then lead to a potential RCE.Patches
Users should upgrade immediately to v1.9.5. All prior versions are vulnerable.
Workarounds
None
References
Fixed by: https://github.com/JuliaRegistries/Registrator.jl/pull/449 (which is available in v1.9.5).
Credits
Thanks to splitline from the DEVCORE Research Team for reporting this issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Registrator