VDB
Sign up
—

GO-2026-4871

Code execution vulnerability in SWIG code generation in cmd/go

Quick fix

GO-2026-4871 — toolchain: upgrade to the fixed version with the command below.

go get toolchain@v1.25.9

Details

SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/toolchain
Introduced in: 0Fixed in: 1.25.9
Fixgo get toolchain@v1.25.9

References