Hunter[verified]@HunterMappingDisclosure
Three new CVEs in Gogs are disclosed, allowing remote code execution and two‑factor authentication bypass, with a CVSS score of 9.3 highlighted by OSINT sources.
VulnTracker[verified]@vuln_trackerGeneral
The tweet merely directs readers to a web page for full details on CVE-2025-64111, without providing additional technical information or actionable indicators.
ThreatSynop[verified]@ThreatSynopPatch
A critical OS command injection in Gogs (≤0.13.3) lets attackers overwrite .git/config via API, enabling remote code execution; users should promptly upgrade to 0.13.4 or later to mitigate the risk.
CVE@CVEnewDisclosure
CVE-2025-64111 affects Gogs versions 0.13.3 and earlier, permitting file updates due to an insufficient patch for CVE-2024-56731.
sckull@sckull_Disclosure
A HackTheBox machine writeup summary disclosing two CVEs: CVE-2025-59528 (RCE for Docker container access) and CVE-2025-64111 (privilege escalation), with basic technical descriptors but no named exploit tools, PoC links, or patches.
PulsePatch.io@pulsepatchioDisclosure
The post announces that Gogs is vulnerable to CVE‑2025‑64111, a critical remote code execution flaw triggered by .git/config file updates, and urges administrators to review the issue.
0day Signal@0dayPublishingDisclosure
Gogs remains vulnerable to CVE‑2025‑64111; a botched patch (CVE‑2024‑56731) still permits RCE via .git/config manipulation, though no active exploitation is reported.