INFSA-2025:13941: golang security update

Information about definition

Identificator: INFSA-2025:13941

Type: security

Release date: 2025-08-27 16:19:34 UTC

Information about package

The golang packages provide the Go programming language compiler.

Vulnerabilities description

  • CVE-2025-4674

    A flaw was found in cmd/go. The go command can execute arbitrary commands when processing untrusted version control system (VCS) repositories containing malicious configuration. This issue occurs because the command interprets VCS metadata, potentially leading to unintended command execution. This vulnerability allows a malicious actor to trigger this by providing a repository with a crafted VCS configuration, resulting in arbitrary code execution within the context of the go process.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
NIST — CVE-2025-4674
no information 8.6 no information
Critical, important, moderate, low

Updated packages