To prevent unexpected untrusted code execution, the Visual Studio Code Go extension is now disabled in Restricted Mode.
References
| Link | Resource |
|---|---|
| https://groups.google.com/g/golang-dev/c/CHG4qfcicBU/m/4tanFUymDQAJ | Mailing List |
| https://nvd.nist.gov/vuln/detail/CVE-2025-68120 | Third Party Advisory |
| https://pkg.go.dev/vuln/GO-2025-4249 | Vendor Advisory |
Configurations
History
06 Jan 2026, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Go go
Go |
|
| CWE | NVD-CWE-noinfo | |
| CPE | cpe:2.3:a:go:go:*:*:*:*:*:visual_studio_code:*:* | |
| References | () https://groups.google.com/g/golang-dev/c/CHG4qfcicBU/m/4tanFUymDQAJ - Mailing List | |
| References | () https://nvd.nist.gov/vuln/detail/CVE-2025-68120 - Third Party Advisory | |
| References | () https://pkg.go.dev/vuln/GO-2025-4249 - Vendor Advisory |
30 Dec 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
30 Dec 2025, 00:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-30 00:15
Updated : 2026-01-06 16:17
NVD link : CVE-2025-68120
Mitre link : CVE-2025-68120
CVE.ORG link : CVE-2025-68120
JSON object : View
Products Affected
go
- go
CWE
