If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.
Conclusion & alert: CVE-2025-47906 is rated Exploit Available (50/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.02%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-09-19 | — | 0.02% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.5 | 3.1 | MEDIUM |
|
3.9 | 2.5 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2025-47906: 1 source package rows (go); 81 state rows across 2 repos (3.22-community, edge-community); fixed 2, open 79. | https://security.alpinelinux.org/vuln/CVE-2025-47906 |
debian
|
not yet assigned | CVE-2025-47906 not yet assigned priority: Debian including 3 source packages (golang-1.15, golang-1.19, golang-1.24), 3 status rows across 3 suites (bookworm, bullseye, trixie): open 3. | https://security-tracker.debian.org/tracker/CVE-2025-47906 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2025-47906 |
suse
|
medium | CVE-2025-47906 severity moderate: SUSE including 81 source package names (cloud-regionsrv-client-10.3.11-3.1, cloud-regionsrv-client-plugin-azure-2.0.0-3.1, …), 399 product×package rows across 33 product lines (Container suse/sl-micro/6.0/baremetal-os-container, Image SLE-Micro, … (33 product lines)): Fixed 358, Known Not Affected 41. | https://www.suse.com/security/cve/CVE-2025-47906/ |
ubuntu
|
medium | CVE-2025-47906 medium priority: Ubuntu including 11 source packages (golang-1.10, golang-1.13, …), 70 status rows across 9 suites (bionic, focal, jammy, noble, plucky, questing, trusty, upstream, xenial): needs-triage 40, DNE 28, ignored 2. | https://ubuntu.com/security/CVE-2025-47906 |
| URL | Tags |
|---|---|
| https://go.dev/cl/691775 | Patch |
| https://go.dev/issue/74466 | Exploit Issue Tracking Third Party Advisory |
| https://groups.google.com/g/golang-announce/c/x5MKroML2yM | Mailing List Release Notes |
| https://pkg.go.dev/vuln/GO-2025-3956 | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2025/08/06/1 | Mailing List Issue Tracking |