PT-2025-28646 · Go +2 · Go +2
Ryotak
·
Published
2025-01-01
·
Updated
2025-07-31
·
CVE-2025-4674
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions:
Go versions prior to 1.24.5
Go versions prior to 1.23.11
Description:
The issue concerns unexpected command execution in untrusted VCS repositories when using the Go toolchain. This can occur when the toolchain is used in directories fetched using VCS tools, such as cloning Git or Mercurial repositories.
Recommendations:
For versions prior to 1.24.5, update to version 1.24.5 to resolve the issue.
For versions prior to 1.23.11, update to version 1.23.11 to resolve the issue.
As a temporary workaround, consider avoiding the use of the Go toolchain in untrusted VCS repositories until a patch is applied.
Related Identifiers
ALT-PU-2025-9085
BIT-GOLANG-2025-4674
CVE-2025-4674
GO-2025-3828
MGASA-2025-0205
SUSE-SU-2025:02295-1
SUSE-SU-2025:02296-1
Affected Products
Alt Linux
Debian
Go
References · 42
- https://osv.dev/vulnerability/SUSE-SU-2025:02295-1 · Vendor Advisory
- https://ubuntu.com/security/CVE-2025-4674 · Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2025-4674 · Vendor Advisory
- https://osv.dev/vulnerability/BIT-golang-2025-4674 · Vendor Advisory
- https://osv.dev/vulnerability/UBUNTU-CVE-2025-4674 · Vendor Advisory
- https://advisories.mageia.org/MGASA-2025-0205.html · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4674 · Security Note
- https://osv.dev/vulnerability/MGASA-2025-0205 · Vendor Advisory
- https://osv.dev/vulnerability/GO-2025-3828 · Vendor Advisory
- https://osv.dev/vulnerability/SUSE-SU-2025:02296-1 · Vendor Advisory
- https://security-tracker.debian.org/tracker/source-package/golang-1.19 · Vendor Advisory
- https://cve.org/CVERecord?id=CVE-2025-4674 · Security Note
- https://errata.altlinux.org/ALT-PU-2025-9085 · Vendor Advisory
- https://osv.dev/vulnerability/CVE-2025-4674 · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-4674 · Security Note