Back to search
CVE-2025-61731
Published: Jan 28, 2026
Modified: Feb 26, 2026
PUBLISHED
Description
Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to the Go pkg-config command. An attacker can provide a "--log-file" argument to this directive, causing pkg-config to write to an attacker-controlled location.
| Vendor | Product | Versions |
|---|---|---|
Go toolchain | cmd/go | affected 0 - < 1.24.12affected 1.25.0 - < 1.25.6 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now