PT-2025-26858 · Unknown · Registrator

Splitline

·

Published

2025-06-16

·

Updated

2025-10-08

·

CVE-2025-52480

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Registrator versions prior to 1.9.5
Description: The issue concerns a GitHub app that automates creation of registration pull requests for julia packages. If the clone URL returned by GitHub is malicious, an argument injection is possible in the gettreesha() function, potentially leading to remote code execution.
Recommendations: For all versions prior to 1.9.5, upgrade immediately to version 1.9.5 to receive a patch. As a temporary workaround, consider restricting the use of the gettreesha() function until the patch is applied.

Exploit

Fix

RCE

Argument Injection

Weakness Enumeration

Related Identifiers

BDU:2025-14505
CVE-2025-52480
GHSA-W8JV-RG3H-FC68
JLSEC-2025-4

Affected Products

Registrator