Junglewise Threat Intelligence

CVE-2025-61731: Google Go argument injection in cmd/go cgo directive

CVE-2025-61731 · Severity: high · CVSS 7.8 · Published 2026-01-28

Technologies: toolchain (Go). Vendors: Google, Go.

Executive brief

A vulnerability in the Go programming language's build tool allows a malicious source file to trigger unauthorized file writes on a developer's system. By including a specially crafted directive in a Go file, an attacker can force the build process to write data to unintended locations, potentially leading to system compromise or arbitrary code execution when the project is built.

Technical details

A vulnerability exists in the 'cmd/go' component of the Go standard library due to insufficient sanitization of flags in the '#cgo pkg-config:' directive. An attacker can bypass flag sanitization by providing a '--log-file' argument within a Go source file, which is then passed to the pkg-config binary. This allows the attacker to trigger a write to an arbitrary file path with partial control over the content. While the primary impact is an unauthorized file write, the Go project notes this can lead to arbitrary code execution. The issue is tracked as CVE-2025-61731 and is fixed in Go versions 1.24.12 and 1.25.6.

Affected products

  • Google Go before 1.24.12, 1.25.0 to 1.25.5

Timeline

  • 2026-01-07: disclosed: Issue opened on Go GitHub repository
  • 2026-01-28: advisory: Official Go security advisory published

References

Related threats