CVE-2025-4674

EUVD-2025-23047
The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.6 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 19.66%
Affected Products (NVD)
VendorProductVersion
golanggo
𝑥
< 1.23.11
golanggo
1.24.0 ≤
𝑥
< 1.24.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
golang-1.15
bullseye
postponed
golang-1.19
bookworm
no-dsa
golang-1.24
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang-1.23
jammy
needed
noble
needed
plucky
ignored
questing
ignored
resolute
needed
golang-1.24
jammy
needed
noble
needed
plucky
ignored
questing
ignored
resolute
not-affected
golang
jammy
dne
noble
dne
plucky
dne
questing
dne
resolute
dne
golang-1.10
bionic
not-affected
jammy
dne
noble
dne
plucky
dne
questing
dne
resolute
dne
trusty
not-affected
xenial
not-affected
golang-1.13
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
dne
plucky
dne
questing
dne
resolute
dne
xenial
ignored
golang-1.14
focal
not-affected
jammy
dne
noble
dne
plucky
dne
questing
dne
resolute
dne
golang-1.16
bionic
not-affected
focal
not-affected
jammy
dne
noble
dne
plucky
dne
questing
dne
resolute
dne
golang-1.17
jammy
not-affected
noble
dne
plucky
dne
questing
dne
resolute
dne
golang-1.18
bionic
needed
focal
needed
jammy
needed
noble
dne
plucky
dne
questing
dne
resolute
dne
xenial
ignored
golang-1.20
focal
needed
jammy
needed
noble
dne
plucky
dne
questing
dne
resolute
dne
golang-1.21
focal
needed
jammy
needed
noble
needed
plucky
dne
questing
dne
resolute
dne
golang-1.22
focal
needed
jammy
needed
noble
needed
plucky
dne
questing
dne
resolute
dne
golang-1.25
jammy
dne
noble
dne
questing
not-affected
resolute
not-affected
golang-1.6
jammy
dne
noble
dne
plucky
dne
questing
dne
resolute
dne
xenial
not-affected
golang-1.8
bionic
not-affected
jammy
dne
noble
dne
plucky
dne
questing
dne
resolute
dne
golang-1.9
bionic
not-affected
jammy
dne
noble
dne
plucky
dne
questing
dne
resolute
dne
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
go-toolset
RHEL 9
0:1.24.6-1.el9_6
fixed
golang
RHEL 9
0:1.24.6-1.el9_6
fixed
golang-bin
RHEL 9
0:1.24.6-1.el9_6
fixed
golang-docs
RHEL 9
0:1.24.6-1.el9_6
fixed
golang-misc
RHEL 9
0:1.24.6-1.el9_6
fixed
golang-race
RHEL 9
0:1.24.6-1.el9_6
fixed
golang-src
RHEL 9
0:1.24.6-1.el9_6
fixed
golang-tests
RHEL 9
0:1.24.6-1.el9_6
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
golang
Amazon Linux 2
0:1.23.11-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.24.5-1.amzn2023.0.1
fixed
golang-bin
Amazon Linux 2
0:1.23.11-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.24.5-1.amzn2023.0.1
fixed
golang-docs
Amazon Linux 2
0:1.23.11-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.24.5-1.amzn2023.0.1
fixed
golang-misc
Amazon Linux 2
0:1.23.11-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.24.5-1.amzn2023.0.1
fixed
golang-shared
Amazon Linux 2
0:1.23.11-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.24.5-1.amzn2023.0.1
fixed
golang-src
Amazon Linux 2
0:1.23.11-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.24.5-1.amzn2023.0.1
fixed
golang-tests
Amazon Linux 2
0:1.23.11-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.24.5-1.amzn2023.0.1
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
golang
CBL-Mariner 2.0
0:1.18.0.cm2
fixed