Critical severity9.8NVD Advisory· Published Jun 25, 2025· Updated Jun 17, 2026
CVE-2025-52480
CVE-2025-52480
Description
Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General registry. Prior to version 1.9.5, if the clone URL returned by GitHub is malicious (or can be injected using upstream vulnerabilities), an argument injection is possible in the gettreesha() function. This can then lead to a potential remote code execution. Users should upgrade immediately to v1.9.5 to receive a patch. All prior versions are vulnerable. No known workarounds are available.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: < 1.9.5
Patches
Vulnerability mechanics
References
2- github.com/JuliaRegistries/Registrator.jl/pull/449nvdIssue TrackingPatch
- github.com/JuliaRegistries/Registrator.jl/security/advisories/GHSA-w8jv-rg3h-fc68nvdIssue TrackingPatchVendor Advisory
News mentions
0No linked articles in our index yet.