Triple Threat: Critical Gogs Flaws (CVSS 9.3) Allow RCE & 2FA Bypass
ID: 67db5fe1-82ab-545b-90a7-71754450e1bf
STIX ID: report--67db5fe1-82ab-545b-90a7-71754450e1bf
Feed Name: securityonline.info
Threat Score
This advisory describes three vulnerabilities in Gogs — a critical RCE (CVE-2025-64111, CVSS 9.3) that allows repository .git/config modification and remote command execution, a 2FA recovery-code cross-account bypass enabling account takeover (CVE-2025-64175, CVSS 7.7), and a wiki path-traversal/file-deletion issue (CVE-2026-24135, CVSS 7.2); maintainers have released fixes and administrators are urged to upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
