
CVE-2025-70963 Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the rendered HTML/Java… https://www.cve.org/CVERecord?id=CVE-2025-70963
Post summary
CVE-2025-70963 affects Gophish versions <=0.12.1, exposing users’ API keys via the admin dashboard due to incorrect access control. No exploit, patch, or active exploitation is mentioned in the text.
