CVE-2025-61731
Arbitrary file write using cgo pkg-config directive in cmd/go
CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th
Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to the Go pkg-config command. An attacker can provide a "--log-file" argument to this directive, causing pkg-config to write to an attacker-controlled location.
| Vendor | go toolchain |
| Product | cmd/go |
| Published | Jan 28, 2026 |
| Last Updated | Feb 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for go toolchain cmd/go
Be the first to know when new high vulnerabilities affecting go toolchain cmd/go are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Go toolchain / cmd/go
0 < 1.24.12 1.25.0 < 1.25.6
References
Credits
RyotaK (https://ryotak.net) of GMO Flatt Security Inc.