CVE Database
/

CVE-2025-4674

Back to search

CVE-2025-4674

Published: Jul 29, 2025

Modified: Nov 4, 2025

PUBLISHED

Description

The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.

VendorProductVersions

Go toolchain

cmd/go

affected
0 - < 1.23.11
affected
1.24.0-0 - < 1.24.5

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now