CVE-2025-52480
Last modified
CVE-2025-52480 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General registry. Prior to version 1.9.5, if the clone URL returned by GitHub is malicious (or can be injected using upstream vulnerabilities), an argument injection is possible in the `gettreesha()` function. EPSS estimates a 0.59% chance of exploitation in the next 30 days.
Description
Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General registry. Prior to version 1.9.5, if the clone URL returned by GitHub is malicious (or can be injected using upstream vulnerabilities), an argument injection is possible in the `gettreesha()` function. This can then lead to a potential remote code execution. Users should upgrade immediately to v1.9.5 to receive a patch. All prior versions are vulnerable. No known workarounds are available.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Julialang | Registrator | < 1.9.5 |
References
- https://github.com/JuliaRegistries/Registrator.jl/pull/449Issue Tracking, Patch
- https://github.com/JuliaRegistries/Registrator.jl/security/advisories/GHSA-w8jv-rg3h-fc68Issue Tracking, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-52480?
How severe is CVE-2025-52480?
How do I fix CVE-2025-52480?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-52475Chamilo is a learning management system. Prior to version 1.…6.1
- CVE-2025-52476Chamilo is a learning management system. Prior to version 1.…6.1
- CVE-2025-52477Octo-STS is a GitHub App that acts like a Security Token Ser…8.6
- CVE-2025-52478n8n is a workflow automation platform. From 1.77.0 to before…5.4
- CVE-2025-52479HTTP.jl provides HTTP client and server functionality for Ju…7.7
- CVE-2025-5248A vulnerability, which was classified as critical, was found…9.8
- CVE-2025-52482Chamilo is a learning management system. Prior to version 1.…8.3
- CVE-2025-52483Registrator is a GitHub app that automates creation of regis…9.8
- CVE-2025-52484RISC Zero is a general computing platform based on zk-STARKs…2.7
- CVE-2025-52485DNN (formerly DotNetNuke) is an open-source web content mana…5.4
- CVE-2025-52486DNN (formerly DotNetNuke) is an open-source web content mana…6.1
- CVE-2025-52487DNN (formerly DotNetNuke) is an open-source web content mana…7.5
Are you affected by CVE-2025-52480?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
