CVE-2025-61731

Published Jan 28, 2026

Last updated 7 days ago

CVSS high 7.8
Golang
Splunk
Mysql

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-61731 describes a vulnerability within the `cmd/go` component of the Go programming language. This flaw involves a bypass of the `CgoPkgConfig` flag. The bypass associated with the `CgoPkgConfig` flag can result in arbitrary code execution. This issue was identified and reported by RyotaK of GMO Flatt Security.

Description
Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to the Go pkg-config command. An attacker can provide a "--log-file" argument to this directive, causing pkg-config to write to an attacker-controlled location.
Source
security@golang.org
NVD status
Modified
Products
go

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
CWE-88

Social media

Hype score
Not currently trending
  1. 🟠 HIGH (CVSS 8.6) — CVE-2025-61731 Published: 2026-01-28 cmd/go: cmd/go: Arbitrary file write via malicious pkg-config directive 🧬 CVSS 3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H #CVE #CyberSecurity #InfoSec #Vulnerability ━━━━━━━━━━

    @CVE2026COIN

    22 Jun 2026

    12 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🔍 Lambda Watchdog detected that CVE-2025-61731 is no longer present in latest AWS Lambda base image scans. https://t.co/djwqDoem3X #AWS #Lambda #Security #CVE #DevOps #SecOps

    @LambdaWatchdog

    23 Feb 2026

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2025-61731 impacts libcap in 20 Lambda base images. Details: https://t.co/djwqDoem3X More: https://t.co/6EUGaPyRZk #AWS #Lambda #CVE #CloudSecurity #Serverless

    @LambdaWatchdog

    8 Feb 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. A high severity arbitrary file write vulnerability (CVE-2025-61731) has been identified in the Go language (golang) cmd/go tool via cgo pkg-config directives. Developers should review build processes. #golang #infosec #vulnerability https://t.co/BARi1zf4I4

    @pulsepatchio

    1 Feb 2026

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2025-61731 Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" dire… https://t.co/10dh76HF77

    @CVEnew

    28 Jan 2026

    189 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🥳 Go 1.26 Release Candidate 2 is released! 🔐 Security: Includes security fixes for archive/zip (CVE-2025-61728), net/http (CVE-2025-61726), crypto/tls (CVE-2025-68121, CVE-2025-61730), cmd/go (CVE-2025-61731, CVE-2025-68119). 🏃‍♀️ Run it in dev! Run it in prod! F

    @golang

    15 Jan 2026

    22045 Impressions

    52 Retweets

    423 Likes

    30 Bookmarks

    4 Replies

    2 Quotes

  7. 🎊 Go 1.25.6 and 1.24.12 are released! 🔐 Security: Includes security fixes for archive/zip (CVE-2025-61728), net/http (CVE-2025-61726), crypto/tls (CVE-2025-68121, CVE-2025-61730), cmd/go (CVE-2025-61731, CVE-2025-68119). 📣 Announcement: https://t.co/seVA1REoeH 📦 Do

    @golang

    15 Jan 2026

    14651 Impressions

    53 Retweets

    279 Likes

    26 Bookmarks

    4 Replies

    3 Quotes

  8. A Go release scheduled for Thursday, Jan 15th covering CVE-2025-61728 CVE-2025-61726 CVE-2025-68121 CVE-2025-61731 CVE-2025-68119, all currently embargoed. Reports of an SSH 0-day, in context of Go's crypto/ssh module.​‌⁣‌⁣‌‌‌‌‌⁣⁣‌‌‌‌⁣‌⁣⁣

    @_mattata

    13 Jan 2026

    327 Impressions

    0 Retweets

    5 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.