{"id":"GO-2025-4249","summary":"Unexpected untrusted code execution in github.com/golang/vscode-go","details":"To prevent unexpected untrusted code execution, the Visual Studio Code Go extension is now disabled in Restricted Mode.","aliases":["CVE-2025-68120","GHSA-fjmr-7667-8v4p"],"modified":"2026-03-17T05:05:45.521546Z","published":"2025-12-29T21:38:26Z","database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2025-4249"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68120"},{"type":"WEB","url":"https://groups.google.com/g/golang-dev/c/CHG4qfcicBU/m/4tanFUymDQAJ"}],"affected":[{"package":{"name":"github.com/golang/vscode-go","ecosystem":"Go","purl":"pkg:golang/github.com/golang/vscode-go"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.52.1"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/golang/vscode-go"}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2025-4249.json"}}],"schema_version":"1.7.5","credits":[{"name":"CHOE WONWOO (https://www.linkedin.com/in/wonwoo-choe-908b11390)"}]}