CVE-2025-61731: Golang Go

High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to the Go pkg-config command. An attacker can provide a "--log-file" argument to this directive, causing pkg-config to write to an attacker-controlled location.

Affected products

  • Golang Go: before 1.24.12 (fixed in 1.24.12); from 1.25.0, before 1.25.6 (fixed in 1.25.6)

Published 2026-01-28. Last modified 2026-09-10.