CVE-2025-52480
CRITICALDescription
Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General registry. Prior to version 1.9.5, if the clone URL returned by GitHub is malicious (or can be injected using upstream vulnerabilities), an argument injection is possible in the `gettreesha()` function. This can then lead to a potential remote code execution. Users should upgrade immediately to v1.9.5 to receive a patch. All prior versions are vulnerable. No known workarounds are available.
Is your site exposed to CVE-2025-52480?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| julialang | registrator |
References
Frequently Asked Questions
What is CVE-2025-52480? +
How severe is CVE-2025-52480? +
What products are affected by CVE-2025-52480? +
How do I check if I'm vulnerable to CVE-2025-52480? +
Related Vulnerabilities
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Nomachine allows Argument Injection.This issue affects Nomachine: before …
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREENS x70 allows Argument Injection.This issue affects …
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations …
Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, src/core/git/gitCommand.ts execGitShallowClone passes the --remote-branch value directly …
A hidden console command is vulnerable to command injection flaw when control characters are passed to its second argument. A …
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution …