#VU124037 Protection mechanism failure in Go programming language - CVE-2025-68119
Published: March 16, 2026
Go programming language
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to usage of unsafe options in Go toolchain. On systems with Mercurial installed (hg) downloading modules from non-standard sources can lead to unexpected code execution due to how external VCS are constructed. A remote attacker can trick the victim into downloading and executing arbitrary code on the target system.