Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2025-47906

Published: August 9, 2025Last modified: August 21, 2025

Description

If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.

Severity score breakdown

ParameterValue
Base score6.5
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactNONE
Availability impactLOW
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSgoFixed (1.23.12-r0)
25 LTSgoFixed (1.24.6-r0)
StreamgoFixed (1.24.6-r0)
Hardened Containers23 LTSgoFixed (1.23.12-r0)
StreamgoFixed (1.24.6-r0)

References

ON THIS PAGE