CVE-2025-61732Code Injection in Toolchain CMD CGO

CWE-94Code Injection8 documents7 sources
Severity
8.6HIGHNVD
EPSS
0.0%
top 99.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 5

Description

A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HExploitability: 1.8 | Impact: 6.0

Affected Packages2 packages

NVDgolang/go1.25.01.25.7+1
CVEListV5go_toolchain/cmd_cgo1.25.0-01.25.7+1

Patches

🔴Vulnerability Details

4
OSV
Potential code smuggling via doc comments in cmd/cgo2026-02-05
OSV
CVE-2025-61732: A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary2026-02-05
CVEList
Potential code smuggling via doc comments in cmd/cgo2026-02-05
GHSA
GHSA-8jvr-vh7g-f8gx: A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary2026-02-05

📋Vendor Advisories

2
Red Hat
cmd/cgo: Go cgo: Code smuggling due to comment parsing discrepancy2026-02-05
Debian
CVE-2025-61732: golang-1.15 - A discrepancy between how Go and C/C++ comments were parsed allowed for code smu...2025

🕵️Threat Intelligence

1
Wiz
CVE-2025-61732 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2025-61732 — Code Injection in GO Toolchain CMD CGO | cvebase