logo

Triple Threat: Critical Gogs Flaws (CVSS 9.3) Allow RCE & 2FA Bypass

ID: 67db5fe1-82ab-545b-90a7-71754450e1bf

STIX ID: report--67db5fe1-82ab-545b-90a7-71754450e1bf

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-02-10

Date Updated: 2026-04-23

Author: Ddos

...
...

This advisory describes three vulnerabilities in Gogs — a critical RCE (CVE-2025-64111, CVSS 9.3) that allows repository .git/config modification and remote command execution, a 2FA recovery-code cross-account bypass enabling account takeover (CVE-2025-64175, CVSS 7.7), and a wiki path-traversal/file-deletion issue (CVE-2026-24135, CVSS 7.2); maintainers have released fixes and administrators are urged to upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.