CNNVD-202506-3189 Information

CNNVD ID

CNNVD-202506-3189

CVE-2025-52483

  • CNNVD Published: 2025-06-25

Description (Chinese)

Julia Registrator.jl是Julia开源的一个Julia包的注册机器人。 Julia Registrator.jl 1.9.5之前版本存在命令注入漏洞,该漏洞源于脚本注入可能导致远程代码执行。

Description (English)

Julia Registrator.jl is a registered Julia package from Julia’s open source. Before Julia Registrator.jl 1.9.5, there was a command-injecting loophole, which originated from a script-injection that could lead to remote code execution.

Hazard Level

High

Vulnerability Type

命令注入

Affected Vendor

Julia

Published

2025-06-25

Last Modified

2026-02-24

References

https://github.com/JuliaRegistries/Registrator.jl/security/advisories/GHSA-589r-g8hf-xx59 https://github.com/JuliaRegistries/Registrator.jl/pull/448 https://nvd.nist.gov/vuln/detail/CVE-2025-52483

Patch

https://github.com/JuliaRegistries/Registrator.jl/releases

Share on: