PT-2025-26859 · Unknown · Registrator

Splitline

·

Published

2025-06-25

·

Updated

2025-10-08

·

CVE-2025-52483

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Registrator versions prior to 1.9.5
Description: The issue concerns a GitHub app that automates creation of registration pull requests for julia packages. A shell script injection can occur within the withpasswd function if the clone URL returned by GitHub is malicious. Alternatively, an argument injection is possible in the gettreesha function, which can lead to a potential remote code execution (RCE).
Recommendations: For all versions prior to 1.9.5, upgrade immediately to version 1.9.5 to receive a fix. As a temporary workaround, consider restricting the use of the withpasswd and gettreesha functions until the issue is resolved.

Exploit

Fix

RCE

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-52483
GHSA-589R-G8HF-XX59
JLSEC-2025-2

Affected Products

Registrator