PT-2025-46010 · Julia · Registrator

Published

2025-10-08

·

Updated

2025-10-08

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.

Impact

If the clone URL returned by GitHub is malicious (or can be injected using upstream vulnerabilities), an argument injection is possible in the gettreesha() function. This can then lead to a potential RCE.

Patches

Users should upgrade immediately to v1.9.5. All prior versions are vulnerable.

Workarounds

None

References

Fixed by: https://github.com/JuliaRegistries/Registrator.jl/pull/449 (which is available in v1.9.5).

Credits

Thanks to splitline from the DEVCORE Research Team for reporting this issue.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

JLSEC-2025-4

Affected Products

Registrator