CVE-2025-4674
Last modified
CVE-2025-4674 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Golang | Go | < 1.23.11 |
| Golang | Go | >= 1.24.0, < 1.24.5 |
References
- https://go.dev/issue/74380Issue Tracking, Third Party Advisory
- https://groups.google.com/g/golang-announce/c/gTNJnDXmn34Mailing List, Release Notes
- https://pkg.go.dev/vuln/GO-2025-3828Vendor Advisory
- http://www.openwall.com/lists/oss-security/2025/07/08/5Mailing List, Release Notes
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-4674?
How severe is CVE-2025-4674?
How do I fix CVE-2025-4674?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-46734league/commonmark is a PHP Markdown parser. A cross-site scr…6.4
- CVE-2025-46735Terraform WinDNS Provider allows users to manage their Windo…1.1
- CVE-2025-46736Umbraco is a free and open source .NET content management sy…5.3
- CVE-2025-46737SEL-5037 Grid Configurator contains an overly permissive Cro…7.4
- CVE-2025-46738An authenticated attacker can maliciously modify layout data…6.6
- CVE-2025-46739An unauthenticated user could discover account credentials v…8.1
- CVE-2025-46740An authenticated user without user administrative permission…7.5
- CVE-2025-46741A suspended or recently logged-out user could continue to in…5.7
- CVE-2025-46742Users who were required to change their password could still…4.3
- CVE-2025-46743An authenticated user's token could be used by another sourc…6.3
- CVE-2025-46744An authenticated administrator could modify the Created By u…2.7
- CVE-2025-46745An authenticated user without user-management permissions co…6.5
Are you affected by CVE-2025-4674?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
