Gogs Flaw Could Let Attackers Quietly Overwrite Large File Storage Data
ID: 78594dd5-e718-5574-8eb1-9ca3c00f084b
STIX ID: report--78594dd5-e718-5574-8eb1-9ca3c00f084b
Feed Name: GBHackers
Threat Score
**CVE-2026-25921 — Critical Gogs LFS overwrite flaw:** A failure to verify uploaded Git LFS object content combined with a global object store in Gogs (versions 0.14.1 and earlier) enables unauthenticated actors to overwrite LFS files across repositories, allowing silent supply-chain compromises; the issue is fixed in Gogs 0.14.2 and administrators should upgrade immediately, validate existing LFS objects for tampering, and restrict access until patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
