CVE-2025-52569 - CVE House
Back to Database
Status published Medium CVE-2025-52569

GitHub.jl lacks validation for user-provided fields

Vulnerability Description

GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 5.9.1 lack input validation of input validation for user-provided values in certain functions. In the `GitHub.repo()` function, the user can provide any string for the `repo_name` field. These inputs are not validated or safely encoded and are sent directly to the server. This means a user can add path traversal patterns like `../` in the input to access any other endpoints on `api.github.com` that were not intended. Users should upgrade immediately to v5.9.1 or later to receive a patch. All prior versions are vulnerable. No known workarounds are available.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-52569

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

GitHub.jl
Vulnerable Versions:
< 5.9.1

Timeline

Official Publish: June 25th, 2025
Last Modified: June 25th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)