To prevent unexpected untrusted code execution, the Visual Studio Code Go extension is now disabled in Restricted Mode.
History

Tue, 06 Jan 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Go
Go go
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:go:go:*:*:*:*:*:visual_studio_code:*:*
Vendors & Products Go
Go go

Mon, 05 Jan 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft visual Studio Code
Vendors & Products Microsoft
Microsoft visual Studio Code

Tue, 30 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Dec 2025 00:00:00 +0000

Type Values Removed Values Added
Description To prevent unexpected untrusted code execution, the Visual Studio Code Go extension is now disabled in Restricted Mode.
Title Unexpected untrusted code execution in github.com/golang/vscode-go
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published: 2025-12-29T23:46:52.451Z

Updated: 2025-12-30T16:05:04.576Z

Reserved: 2025-12-15T16:48:04.451Z

Link: CVE-2025-68120

cve-icon Vulnrichment

Updated: 2025-12-30T16:04:58.866Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-30T00:15:52.333

Modified: 2026-01-06T16:17:16.943

Link: CVE-2025-68120

cve-icon Redhat

No data.