PT-2025-26858 · Unknown · Registrator
Splitline
·
Published
2025-06-16
·
Updated
2025-10-08
·
CVE-2025-52480
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Registrator versions prior to 1.9.5
Description:
The issue concerns a GitHub app that automates creation of registration pull requests for julia packages. If the clone URL returned by GitHub is malicious, an argument injection is possible in the
gettreesha() function, potentially leading to remote code execution.Recommendations:
For all versions prior to 1.9.5, upgrade immediately to version 1.9.5 to receive a patch.
As a temporary workaround, consider restricting the use of the
gettreesha() function until the patch is applied.Exploit
Fix
RCE
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Registrator