CVE-2025-4674Patch(golang / go)

LOWCVSS 8.6 · HIGH

Signal is active with 6 mentions in latest observed window

Immediate actions

  • Patch golang go systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 6 signals
  • 6 total mentions across 1 day

Affected systems

Vendors
Products
go

Deep dive

Activity timeline6 mentions / 1d
02356Mentions · 2026-03-11: 6Patch / Workaround · 2026-03-11: 603-11
Signal classification1 categories
Patch
6100.0%
Full discourse6 posts
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 CVE-2025-47907 CVE-2025-4674 N/A Security fixes for 18/19

    Post summary

    The text lists several CVEs that are addressed by security fixes, indicating patch availability but providing no exploitation details.

    10000108
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-58188 CVE-2025-58187 CVE-2026-24051 CVE-2025-68119 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-4674 N/A Security fixes for apigee-redis 17/19

    Post summary

    The statement lists several CVE identifiers and announces security fixes for apigee-redis 17/19, indicating a patch/update notification.

    1000091
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-58188 CVE-2025-58187 CVE-2026-24051 CVE-2025-68119 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-47913 CVE-2025-4674 N/A Security fixes for apigee-prometheus-adapter 16/19

    Post summary

    This release note reports that Apigee Prometheus Adapter version 16/19 includes security fixes for a set of listed CVEs, but does not provide PoC, exploit, or technical vulnerability details.

    1000097
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-58188 CVE-2025-58187 CVE-2026-24051 CVE-2025-68156 CVE-2025-61729 CVE-2025-4674 CVE-2025-29786 N/A Security fixes for apigee-open-telemetry-collector: 14/19

    Post summary

    The text identifies multiple CVEs linked to the apigee-open-telemetry-collector and notes that 14 of 19 security fixes have been applied.

    1000085
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    CVE-2025-47907 CVE-2025-4674 N/A Security fixes for apigee-kube-rbac-proxy. This addresses the following vulnerabilities: CVE-2025-61729 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 CVE-2026-24051 N/A Security fixes for apigee-open-telemetry-collector 13/19

    Post summary

    The text lists several CVE identifiers and indicates that security fixes are available for apigee-kube-rbac-proxy and apigee-open-telemetry-collector components.

    1000085
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    apigee-asm-ingress. This addresses the following vulnerability: CVE-2026-24051 N/A Security fixes for apigee-connect-agent. This addresses the following vulnerabilities: CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-4674 11/19

    Post summary

    The entry lists several CVEs and indicates that security fixes are available for Apigee products, without providing detailed vulnerability or exploitation information.

    1000097
    1.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgolanggo---

Explore more