CVE-2025-68119Patch(golang / go)

LOWCVSS 7.0 · HIGH

Signal is active with 6 mentions in latest observed window

Immediate actions

  • Patch golang go systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked at 6 mentions on most recent observed day (2026-03-11)
  • 9 total mentions across 4 days

Affected systems

Vendors
Products
go

Deep dive

Activity timeline9 mentions / 4d
02356Mentions · 2026-01-28: 1Mentions · 2026-02-01: 1Mentions · 2026-02-23: 1Mentions · 2026-03-11: 6Patch / Workaround · 2026-02-01: 1Patch / Workaround · 2026-02-23: 1Patch / Workaround · 2026-03-11: 5Technical Details · 2026-01-28: 1Technical Details · 2026-02-01: 101-2802-0102-2303-11
Signal classification2 categories
Patch
888.9%
Disclosure
111.1%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-281
Disclosure1
2026-02-011
Patch1
2026-02-231
Patch1
2026-03-116
Patch6
Full discourse9 posts
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 CVE-2025-47907 CVE-2025-4674 N/A Security fixes for 18/19

    Post summary

    The statement lists multiple CVEs and notes that security fixes are available for affected products.

    10000108
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-58188 CVE-2025-58187 CVE-2026-24051 CVE-2025-68119 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-4674 N/A Security fixes for apigee-redis 17/19

    Post summary

    Apigee-redis 17/19 releases security fixes addressing the listed CVEs, without any evidence of PoC, exploits, or active exploitation.

    1000091
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-58188 CVE-2025-58187 CVE-2026-24051 CVE-2025-68119 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-47913 CVE-2025-4674 N/A Security fixes for apigee-prometheus-adapter 16/19

    Post summary

    The note lists several CVE identifiers that have been addressed through security fixes in the apigee‑prometheus‑adapter version 16/19, indicating a patch release.

    1000097
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    N/A Security fixes for apigee-hybrid-cassandra-client. This addresses the following vulnerabilities: CVE-2026-24051 CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 12/19

    Post summary

    The note announces security fixes for a set of CVEs in apigee-hybrid-cassandra-client, indicating that patches have been released.

    1000081
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    apigee-asm-ingress. This addresses the following vulnerability: CVE-2026-24051 N/A Security fixes for apigee-connect-agent. This addresses the following vulnerabilities: CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-4674 11/19

    Post summary

    The snippet lists CVEs that have been fixed in apigee‑asm‑ingress and apigee‑connect‑agent, indicating that security patches are in place, with no evidence of PoC, exploit, or active exploitation.

    1000097
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    apigee-stackdriver-logging-agent. This addresses the following vulnerabilities: CVE-2026-24051 CVE-2025-68121 CVE-2025-68119 CVE-2025-61732 CVE-2025-61731 CVE-2025-61729 CVE-2025-61726 CVE-2025-61725 CVE-2025-61723 CVE-2025-58188 CVE-2025-58187 CVE-2025-47907. 19/19

    Post summary

    The message lists a set of CVEs that the apigee‑stackdriver‑logging‑agent claims to address, but it provides no explicit details about patches, exploit availability, or technical characteristics.

    00000116
    1.8K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2025-68119 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/400 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    AWS Lambda base images have been updated to remove CVE-2025-68119, indicating the vulnerability has been patched or removed from the images.

    0000035
    30 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A high severity code execution vulnerability (CVE-2025-68119) affects the Go toolchain. Update Go to 1.25.6 to mitigate risks in #development and #CI/CD environments. #golang https://www.pulsepatch.io/posts/cve-2025-68119-golang-code-execution

    Post summary

    The tweet highlights a high‑severity code execution flaw in the Go toolchain (CVE‑2025‑68119) and advises users to update to Go 1.25.6 for mitigation.

    0000065
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-68119 Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non… https://www.cve.org/CVERecord?id=CVE-2025-68119

    Post summary

    The tweet announces CVE‑2025‑68119, noting that malicious version strings in Mercurial modules can lead to local code execution.

    00000193
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgolanggo---

Explore more