Gogs Vulnerability Enables Attackers to Silently Overwrite Large File Storage Objects
ID: 3ddea4c1-3a59-5dde-b7e4-3d985429e7ed
STIX ID: report--3ddea4c1-3a59-5dde-b7e4-3d985429e7ed
Feed Name: cybersecurityNews.com
A critical vulnerability (CVE-2026-25921, CVSS 3.1 score 10.0) in Gogs (<= 0.14.1) lets attackers overwrite shared Large File Storage (LFS) objects by uploading a manipulated file that claims a victim’s SHA-256 OID; because storage is not isolated by repository and uploads are not verified, this enables undetectable supply-chain tampering across repositories. No official patch was available at disclosure; recommended temporary mitigations include restricting LFS upload permissions and performing manual SHA-256 integrity checks until server-side hash verification is implemented.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
