← Vulnerability feed

Vulnerability record · CVE-2025-61731 · published 28 January 2026

CVE-2025-61731: Golang go argument injection vulnerability

Golang · Go

Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to the Go pkg-config command. An attacker can provide a "--log-file" argument to this directive, causing pkg-config to write to an attacker-controlled location.

7.8 CVSS 3.1 High EPSS 0.62% · top 52.4% CWE-88 · Argument injection
7.8CVSS 3.1 base score
0.62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
38References
10 Sep 2026Last modified by NVD

Description

Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to the Go pkg-config command. An attacker can provide a "--log-file" argument to this directive, causing pkg-config to write to an attacker-controlled location.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://go.dev/cl/736711 Patch
https://go.dev/issue/77100 Issue Tracking
https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc Mailing ListRelease Notes
https://pkg.go.dev/vuln/GO-2026-4339 Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:12118
https://access.redhat.com/errata/RHSA-2026:12282
https://access.redhat.com/errata/RHSA-2026:13736
https://access.redhat.com/errata/RHSA-2026:14100
https://access.redhat.com/errata/RHSA-2026:14774
https://access.redhat.com/errata/RHSA-2026:15091
https://access.redhat.com/errata/RHSA-2026:17598
https://access.redhat.com/errata/RHSA-2026:20088
https://access.redhat.com/errata/RHSA-2026:21691
https://access.redhat.com/errata/RHSA-2026:3556
https://access.redhat.com/errata/RHSA-2026:3559
https://access.redhat.com/errata/RHSA-2026:3855
https://access.redhat.com/errata/RHSA-2026:4434
https://access.redhat.com/errata/RHSA-2026:5941
https://access.redhat.com/errata/RHSA-2026:5942
https://access.redhat.com/errata/RHSA-2026:5943
https://access.redhat.com/errata/RHSA-2026:5944
https://access.redhat.com/errata/RHSA-2026:5948
https://access.redhat.com/errata/RHSA-2026:5950
https://access.redhat.com/errata/RHSA-2026:5952
https://access.redhat.com/errata/RHSA-2026:6949
https://access.redhat.com/errata/RHSA-2026:7291
https://access.redhat.com/errata/RHSA-2026:7385
https://access.redhat.com/errata/RHSA-2026:7833
https://access.redhat.com/errata/RHSA-2026:7834
https://access.redhat.com/errata/RHSA-2026:7876
https://access.redhat.com/errata/RHSA-2026:7877
https://access.redhat.com/errata/RHSA-2026:7878
https://access.redhat.com/errata/RHSA-2026:7879
https://access.redhat.com/errata/RHSA-2026:7883
https://access.redhat.com/errata/RHSA-2026:8448
https://access.redhat.com/security/cve/CVE-2025-61731
https://bugzilla.redhat.com/show_bug.cgi?id=2434433
https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61731.json

Track CVE-2025-61731 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2020-0601Windows CryptoAPI ECC certificate validation spoofing flawWindows CryptoAPI (Crypt32.dll) improperly validates Elliptic Curve Cryptography certificates, allowing a spoofed code-signing certificate to be trus…KEVEPSS 89%analysed7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed10.0CVE-2025-68121Golang go improper certificate validation vulnerabilityDuring session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the r…EPSS 0.86%9.8CVE-2026-27143Golang go vulnerabilityArithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid …EPSS 0.66%9.8CVE-2024-24790Golang go vulnerabilityThe various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which woul…EPSS 2.0%9.8CVE-2023-39320Golang go code injection vulnerabilityThe go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "…EPSS 1.8%9.8CVE-2023-29404Golang go code injection vulnerabilityThe go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running a…EPSS 1.8%9.8CVE-2023-29405Golang go injection vulnerabilityThe go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running a…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2025-61731), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.