PT-2025-46010 · Julia · Registrator
Published
2025-10-08
·
Updated
2025-10-08
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Impact
If the clone URL returned by GitHub is malicious (or can be injected using upstream vulnerabilities), an argument injection is possible in the
gettreesha() function. This can then lead to a potential RCE.Patches
Users should upgrade immediately to v1.9.5. All prior versions are vulnerable.
Workarounds
None
References
Fixed by: https://github.com/JuliaRegistries/Registrator.jl/pull/449 (which is available in v1.9.5).
Credits
Thanks to splitline from the DEVCORE Research Team for reporting this issue.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Registrator