Executive brief
A vulnerability in the Go programming language's 'cgo' tool could allow malicious code to be hidden within what appears to be harmless documentation comments. If a developer builds a project containing this specially crafted code, the hidden instructions could be executed as part of the resulting application. This could lead to unauthorized data access or full system compromise during the software development and build process.
Technical details
A code injection vulnerability exists in the cmd/cgo component of the Go standard library due to semantic differences in comment parsing between the Go compiler and the C/C++ compiler. An attacker can craft source code where certain strings are treated as harmless comments by the Go compiler but interpreted as executable code by the C compiler during the cgo translation process. This 'code smuggling' allows for the execution of arbitrary C code when the Go binary is built. The issue is triggered during the build process and typically requires a user to compile untrusted source code. Patches are available in Go versions 1.24.13 and 1.25.7.
Affected products
- Google Go (golang) before 1.24.13, 1.25.0 to 1.25.6
Timeline
- 2025-12-04: disclosed: Issue reported to the Go project by RyotaK
- 2026-02-05: advisory: Public advisory and CVE published
- 2026-02-05: patched: Fixed in Go 1.24.13 and 1.25.7