CVE-2025-4674: Unexpected command execution in untrusted VCS repositories in cmd/go

Published Jul 8, 2025
·
Updated

The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.

Affected Software

3 affected components
Google Go>=1.23.11<=1.24.5
Golang Go<1.23.11
Golang Go>=1.24.0<1.24.5

Remediation

Event History

Jul 29, 2025
CVE Published
via MITRE·09:19 PM
Data Sourced
via MITRE·09:19 PM
DescriptionWeakness
Data Sourced
via Red Hat·10:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-4674?

CVE-2025-4674 has been classified as a moderate severity vulnerability due to its potential to execute unexpected commands.

2

How do I fix CVE-2025-4674?

To fix CVE-2025-4674, ensure that you only use trusted VCS repositories and avoid mixing metadata from different VCS systems.

3

What software is affected by CVE-2025-4674?

CVE-2025-4674 affects the Go programming language's command-line tools when used with untrusted version control systems.

4

What types of VCS configurations are involved in CVE-2025-4674?

CVE-2025-4674 involves potentially dangerous VCS configurations resulting from mixed repository metadata.

5

Can CVE-2025-4674 lead to remote code execution?

While CVE-2025-4674 can lead to unexpected command execution, it does not directly cause remote code execution without further exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203