Логотип exploitDog
bind:CVE-2025-68119
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-68119

Количество 12

Количество 12

ubuntu логотип

CVE-2025-68119

11 дней назад

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2025-68119

11 дней назад

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.

CVSS3: 7
EPSS: Низкий
debian логотип

CVE-2025-68119

11 дней назад

Downloading and building modules with malicious version strings can ca ...

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-cm6p-qc7v-m3jw

11 дней назад

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.

CVSS3: 7
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20085-1

17 дней назад

Security update for go1.25

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20077-1

18 дней назад

Security update for go1.24

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0219-1

18 дней назад

Security update for go1.24

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0218-1

18 дней назад

Security update for go1.25

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0308-1

12 дней назад

Security update for go1.24-openssl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0296-1

13 дней назад

Security update for go1.24-openssl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0298-1

13 дней назад

Security update for go1.25-openssl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0297-1

13 дней назад

Security update for go1.25-openssl

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-68119

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.

CVSS3: 7
0%
Низкий
11 дней назад
nvd логотип
CVE-2025-68119

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.

CVSS3: 7
0%
Низкий
11 дней назад
debian логотип
CVE-2025-68119

Downloading and building modules with malicious version strings can ca ...

CVSS3: 7
0%
Низкий
11 дней назад
github логотип
GHSA-cm6p-qc7v-m3jw

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.

CVSS3: 7
0%
Низкий
11 дней назад
suse-cvrf логотип
openSUSE-SU-2026:20085-1

Security update for go1.25

17 дней назад
suse-cvrf логотип
openSUSE-SU-2026:20077-1

Security update for go1.24

18 дней назад
suse-cvrf логотип
SUSE-SU-2026:0219-1

Security update for go1.24

18 дней назад
suse-cvrf логотип
SUSE-SU-2026:0218-1

Security update for go1.25

18 дней назад
suse-cvrf логотип
SUSE-SU-2026:0308-1

Security update for go1.24-openssl

12 дней назад
suse-cvrf логотип
SUSE-SU-2026:0296-1

Security update for go1.24-openssl

13 дней назад
suse-cvrf логотип
SUSE-SU-2026:0298-1

Security update for go1.25-openssl

13 дней назад
suse-cvrf логотип
SUSE-SU-2026:0297-1

Security update for go1.25-openssl

13 дней назад

Уязвимостей на страницу