Critical severity9.8NVD Advisory· Published Jun 25, 2025· Updated Jun 17, 2026
CVE-2025-52483
CVE-2025-52483
Description
Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General registry. Prior to version 1.9.5, if the clone URL returned by GitHub is malicious (or can be injected using upstream vulnerabilities) a shell script injection can occur within the withpasswd function. Alternatively, an argument injection is possible in the gettreesha function. either of these can then lead to a potential RCE. Users should upgrade immediately to v1.9.5 to receive a fix. All prior versions are vulnerable. No known workarounds are available.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4<1.9.5+ 1 more
- (no CPE)range: <1.9.5
- (no CPE)range: < 1.9.5
Patches
Vulnerability mechanics
References
2- github.com/JuliaRegistries/Registrator.jl/pull/448nvdIssue TrackingPatch
- github.com/JuliaRegistries/Registrator.jl/security/advisories/GHSA-589r-g8hf-xx59nvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.