CVE-2025-68120: Go

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

To prevent unexpected untrusted code execution, the Visual Studio Code Go extension is now disabled in Restricted Mode.

Affected products

  • Go Go: before 0.52.1 (fixed in 0.52.1)

Published 2025-12-30. Last modified 2026-10-01.