CVE-2025-61731Patch(golang / go)

LOWCVSS 7.8 · HIGH

Signal is active with 6 mentions in latest observed window

Immediate actions

  • Patch golang go systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to the Go pkg-config command. An attacker can provide a "--log-file" argument to this directive, causing pkg-config to write to an attacker-controlled location.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-88

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 5 observed days
  • Momentum state: rising

What's happening

  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 6 mentions on most recent observed day (2026-03-11)
  • 10 total mentions across 5 days

Affected systems

Vendors
Products
go

Deep dive

Activity timeline10 mentions / 5d
02356Mentions · 2026-01-28: 1Mentions · 2026-01-29: 1Mentions · 2026-02-01: 1Mentions · 2026-02-23: 1Mentions · 2026-03-11: 6Patch / Workaround · 2026-02-23: 1Patch / Workaround · 2026-03-11: 6Technical Details · 2026-01-28: 1Technical Details · 2026-01-29: 1Technical Details · 2026-02-01: 101-2801-2902-0102-2303-11
Signal classification2 categories
Patch
770.0%
Disclosure
330.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-281
Disclosure1
2026-01-291
Disclosure1
2026-02-011
Disclosure1
2026-02-231
Patch1
2026-03-116
Patch6
Full discourse10 posts
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 CVE-2025-47907 CVE-2025-4674 N/A Security fixes for 18/19

    Post summary

    The notice lists multiple CVE identifiers and states that security fixes are available for versions 18/19, but provides no technical or exploit details.

    10000108
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-58188 CVE-2025-58187 CVE-2026-24051 CVE-2025-68119 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-4674 N/A Security fixes for apigee-redis 17/19

    Post summary

    This text announces that apigee‑redis versions 17 and 19 have received security fixes for a set of CVEs.

    1000091
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-58188 CVE-2025-58187 CVE-2026-24051 CVE-2025-68119 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-47913 CVE-2025-4674 N/A Security fixes for apigee-prometheus-adapter 16/19

    Post summary

    The post lists several CVE identifiers and notes that security fixes have been applied to apigee-prometheus-adapter version 16/19.

    1000097
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    N/A Security fixes for apigee-hybrid-cassandra-client. This addresses the following vulnerabilities: CVE-2026-24051 CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 12/19

    Post summary

    Security update for Apigee hybrid Cassandra client includes fixes for multiple CVEs. No PoC, exploit, or active exploitation information is provided.

    1000081
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    apigee-asm-ingress. This addresses the following vulnerability: CVE-2026-24051 N/A Security fixes for apigee-connect-agent. This addresses the following vulnerabilities: CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-4674 11/19

    Post summary

    The text announces that security fixes for apigee-connect-agent address a set of CVEs, indicating patch availability but no additional technical or exploit details.

    1000097
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    apigee-stackdriver-logging-agent. This addresses the following vulnerabilities: CVE-2026-24051 CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 CVE-2025-47907. 19/19

    Post summary

    The message indicates that the apigee-stackdriver-logging-agent update patches a list of CVEs.

    00000116
    1.8K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2025-61731 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/399 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The CVE‑2025‑61731 vulnerability has been addressed and is no longer present in the latest AWS Lambda base images, indicating a patch or removal.

    0000039
    30 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A high severity arbitrary file write vulnerability (CVE-2025-61731) has been identified in the Go language (golang) cmd/go tool via cgo pkg-config directives. Developers should review build processes. #golang #infosec #vulnerability https://www.pulsepatch.io/posts/cve-2025-61731-golang-arbitrary-file-write

    Post summary

    A high‑severity arbitrary file write vulnerability (CVE‑2025‑61731) was identified in Go’s cmd/go tool via cgo pkg‑config directives; developers are advised to review build processes.

    0000070
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-61731 Go pkg-config Directive Vulnerability Allows Arbitrary File Write https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-61731

    Post summary

    The text announces CVE-2025-61731, a Go pkg-config directive vulnerability that permits arbitrary file writes, without providing a PoC, exploit code, or patch information.

    0000093
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-61731 Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" dire… https://www.cve.org/CVERecord?id=CVE-2025-61731

    Post summary

    The text announces CVE‑2025‑61731, explaining that an attacker can cause a file write with partial content control via a malicious Go build, but provides no PoC, exploit details, patch, or evidence of active exploitation.

    00000332
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgolanggo---

Explore more