CVE-2025-68120: Unexpected untrusted code execution in github.com/golang/vscode-go
To prevent unexpected untrusted code execution, the Visual Studio Code Go extension is now disabled in Restricted Mode.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68120?
CVE-2025-68120 is classified as a high severity vulnerability due to the risk of untrusted code execution.
How do I fix CVE-2025-68120?
To address CVE-2025-68120, ensure that the Visual Studio Code Go extension is disabled in Restricted Mode.
What software is affected by CVE-2025-68120?
CVE-2025-68120 affects the Visual Studio Code Go extension, particularly versions associated with the GitHub repository github.com/golang/vscode-go.
What does CVE-2025-68120 mean for users of the Go extension?
CVE-2025-68120 indicates that users of the Go extension should be cautious about executing code, as the extension can introduce security risks.
Is there a workaround for CVE-2025-68120?
The primary workaround for CVE-2025-68120 is to operate Visual Studio Code in Restricted Mode, which prevents the extension from running untrusted code.