VYPR
Unrated severityNVD Advisory· Published Sep 18, 2025· Updated Nov 4, 2025

Unexpected paths returned from LookPath in os/exec

CVE-2025-47906

Description

If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.

Affected products

1
  • Go standard library/os/execv5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.