7.8highHigh

CVE-2025-61731

Golang Go

Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to the Go pkg-config command. An attacker can provide a "--log-file" argument to this directive, causing pkg-config to write to an attacker-controlled location.

Exploitation status

  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is requires local access to the machine.
  • For an attacker who can reach it, no special conditions are needed to exploit it.
  • To exploit it, an ordinary user account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
7.8 (v3.1)
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness
CWE-88
Assigned by
security@golang.org

Dates

Published
2026-01-28
Last modified
2026-08-26
Sources
NVD

Affected products

  • Golang Go- 1.24.12, 1.25.0 - 1.25.6

As listed in the NVD configuration data. Not a statement about your estate.

References