CVE-2025-52483 is a critical vulnerability affecting the Registrator GitHub app for Julia package registration, specifically versions prior to 1.9.5. It allows for remote code execution (RCE) through shell script injection in the withpasswd function or argument injection in the gettreesha function, triggered by a malicious or injected GitHub clone URL. With a CVSS score of 9.8 (CRITICAL), this vulnerability has a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While there are no known exploits in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community discussion, indicating high awareness. Users are urged to upgrade to Registrator v1.9.5 immediately as no workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.9.5CPE matchmatch criteria | cpe:2.3:a:julialang:registrator:*:*:*:*:*:julia:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.