CVE-2025-68119
Unexpected code execution when invoking toolchain in cmd/go
描述
Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.
如何修補 CVE-2025-68119
要修補 CVE-2025-68119,請將受影響套件升級到下列已修補版本。
- —升級至 1.25.6 或更新版本
- —未列出修補版本
- —未列出修補版本
- —未列出修補版本
- —升級至 1.25.6-1 或更新版本
- —升級至 1.25.6 或更新版本
CVE-2025-68119 正在被利用嗎?
低 — EPSS 為 0.3%,目前沒有觀察到大規模利用活動。
受影響套件(6)
- >= 1.25.0, < 1.25.6
- from 0
- from 0
- from 0
- from 0, < 1.25.6-1
- >= 1.25.0, < 1.25.6
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.0 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |