PT-2025-26859 · Unknown · Registrator
Splitline
·
Published
2025-06-25
·
Updated
2025-10-08
·
CVE-2025-52483
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Registrator versions prior to 1.9.5
Description:
The issue concerns a GitHub app that automates creation of registration pull requests for julia packages. A shell script injection can occur within the
withpasswd function if the clone URL returned by GitHub is malicious. Alternatively, an argument injection is possible in the gettreesha function, which can lead to a potential remote code execution (RCE).Recommendations:
For all versions prior to 1.9.5, upgrade immediately to version 1.9.5 to receive a fix.
As a temporary workaround, consider restricting the use of the
withpasswd and gettreesha functions until the issue is resolved.Exploit
Fix
RCE
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Registrator