VDB

CVE-2025-68120

CVE-2025-68120 PUBLISHED CVSS 5.400000095367432 MEDIUM

Visual Studio Code Go extension has unexpected untrusted code execution

EPSS 0.03% · 8.2th percentile

Risk Scores

CVSS v3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
EPSS Score
0.03%
8.2th percentile

Affected Products

VendorProductVersions
github.comgolang/vscode-go0
github.com/golang/vscode-gogithub.com/golang/vscode-go0
gogo0

Timeline

  • Dec 29, 2025 CVE Published
  • Dec 30, 2025 EPSS Score
  • Dec 30, 2025 PoC Published
  • Dec 30, 2025 PoC Published
  • Jan 2, 2026 EPSS Score
  • Jan 6, 2026 EPSS Score
  • Jan 6, 2026 CVE Updated
  • Jan 9, 2026 EPSS Score
  • Jan 13, 2026 EPSS Score
  • Jan 16, 2026 EPSS Score
  • Jan 20, 2026 EPSS Score
  • Jan 23, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›