CVE-2025-68119 - CVE House
Back to Database
Status published Unknown CVE-2025-68119

Unexpected code execution when invoking toolchain in cmd/go

Vulnerability Description

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-68119

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • splitline (@splitline) from DEVCORE Research Team

Affected Vendor

Go toolchain

View all reports →

Affected Software

cmd/go
Vulnerable Versions:
1.25.0

Timeline

Official Publish: January 28th, 2026
Last Modified: February 26th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.