CVE-2025-64111Disclosure(gogs / gogs)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gogs gogs systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, due to the insufficient patch for CVE-2024-56731, it's still possible to update files in the .git directory and achieve remote command execution. This issue has been patched in versions 0.13.4 and 0.14.0+dev.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gogs

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-02-06); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
gogs

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-02-06: 2Mentions · 2026-02-07: 1Mentions · 2026-02-10: 2Mentions · 2026-02-11: 1Mentions · 2026-09-18: 1Patch / Workaround · 2026-02-06: 1Patch / Workaround · 2026-02-10: 1Technical Details · 2026-02-06: 1Technical Details · 2026-02-07: 1Technical Details · 2026-02-10: 2Technical Details · 2026-09-18: 102-0602-0702-1002-1109-18
Signal classification3 categories
Disclosure
571.4%
Patch
114.3%
General
114.3%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-02-062
Disclosure2
2026-02-071
Disclosure1
2026-02-102
Disclosure1Patch1
2026-02-111
General1
2026-09-181
Disclosure1
Full discourse7 posts
  • Hunter@HunterMapping
    Disclosure

    🚨Alert🚨 CVE-2025-64111 & CVE-2025-64175 & CVE-2026-24135 : Critical Gogs Flaws Allow RCE & 2FA Bypass. 📊 319K+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Gogs%22 👇Query HUNTER : http://product.name="Gogs" 📰Refer:https://securityonline.info/triple-threat-critical-gogs-flaws-cvss-9-3-allow-rce-2fa-bypass/ #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    Three new CVEs in Gogs are disclosed, allowing remote code execution and two‑factor authentication bypass, with a CVSS score of 9.3 highlighted by OSINT sources.

    115038163.4K
    25.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-64111 Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, due to the insufficient patch for CVE-2024-56731, it's still possible to update files in … https://www.cve.org/CVERecord?id=CVE-2025-64111

    Post summary

    CVE-2025-64111 affects Gogs versions 0.13.3 and earlier, permitting file updates due to an insufficient patch for CVE-2024-56731.

    00010161
    56.5K followersView on X
  • sckull@sckull_
    Disclosure

    HackTheBox - Silentium 🔓 Flowise -> cambio de contraseña. 💥 CVE-2025-59528 (RCE) acceso a contenedor Docke 🔑 Credenciales en variables de entorno 🚀 Privesc via CVE-2025-64111 https://sckull.github.io/posts/silentium/

    Post summary

    A HackTheBox machine writeup summary disclosing two CVEs: CVE-2025-59528 (RCE for Docker container access) and CVE-2025-64111 (privilege escalation), with basic technical descriptors but no named exploit tools, PoC links, or patches.

    0000074
    179 followersView on X
  • VulnTracker@vuln_tracker
    General

    @the_yellow_fall You now can see the full detail about CVE-2025-64111 from https://vulntracker.io/cves/CVE-2025-64111

    Post summary

    The tweet merely directs readers to a web page for full details on CVE-2025-64111, without providing additional technical information or actionable indicators.

    0000035
    333 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Critical Gogs RCE Bug Lets Attackers Rewrite .git/config via API (CVE-2025-64111) A critical OS command injection in Gogs (≤0.13.3) abuses a symlink + repository contents API to overwrite `.git/config` and inject malicious Git config (e.g., sshCommand), enabling remote code execution during Git operations. Upgrade to 0.13.4 (or 0.14.0+dev) immediately because this turns a source-control server into a direct foothold for supply-chain compromise and lateral movement. 🎯 Target: Global/DevOps (Self-hosted Git) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/gogs-vulnerability/

    Post summary

    A critical OS command injection in Gogs (≤0.13.3) lets attackers overwrite .git/config via API, enabling remote code execution; users should promptly upgrade to 0.13.4 or later to mitigate the risk.

    0000057
    191 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    Gogs is affected by CVE-2025-64111, a critical RCE vulnerability enabling remote command execution via .git/config file updates. Admins should review. #Gogs #Git #InfoSec https://www.pulsepatch.io/posts/cve-2025-64111-gogs-remote-command-execution

    Post summary

    The post announces that Gogs is vulnerable to CVE‑2025‑64111, a critical remote code execution flaw triggered by .git/config file updates, and urges administrators to review the issue.

    0000079
    1 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-64111: Gogs's update .git/config file a... Botched patch for Gogs (CVE-2024-56731) still lets attackers manipulate .git/config for RCE - trivial to exploit with z... https://zerodaysignal.com/vulnerability/CVE-2025-64111 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    Gogs remains vulnerable to CVE‑2025‑64111; a botched patch (CVE‑2024‑56731) still permits RCE via .git/config manipulation, though no active exploitation is reported.

    0000094
    132 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgogsgogs---

Explore more