Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-4674

Опубликовано: 29 июл. 2025
Источник: nvd
CVSS3: 8.6
EPSS Низкий

Описание

The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.

EPSS

Процентиль: 4%
0.00023
Низкий

8.6 High

CVSS3

Дефекты

CWE-73

Связанные уязвимости

CVSS3: 8.6
ubuntu
20 дней назад

The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.

CVSS3: 8.6
redhat
20 дней назад

The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.

CVSS3: 8.6
debian
20 дней назад

The go command may execute unexpected commands when operating in untru ...

suse-cvrf
около 1 месяца назад

Security update for go1.23

suse-cvrf
около 1 месяца назад

Security update for go1.24

EPSS

Процентиль: 4%
0.00023
Низкий

8.6 High

CVSS3

Дефекты

CWE-73