Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-52480


Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General registry. Prior to version 1.9.5, if the clone URL returned by GitHub is malicious (or can be injected using upstream vulnerabilities), an argument injection is possible in the `gettreesha()` function. This can then lead to a potential remote code execution. Users should upgrade immediately to v1.9.5 to receive a patch. All prior versions are vulnerable. No known workarounds are available.


Published

2025-06-25T17:15:38.590

Last Modified

2025-09-19T16:02:53.687

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-88

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application julialang registrator < 1.9.5 Yes

References