CVE-2025-70963Disclosure(getgophish / gophish)

LOWCVSS 7.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the rendered HTML/JavaScript of the page on every login. This makes permanent API credentials accessible to any script running in the browser context.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-922

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gophish

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
gophish

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-06: 1Technical Details · 2026-02-06: 102-06
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CVE@CVEnew
    Disclosure

    CVE-2025-70963 Gophish &lt;=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the rendered HTML/Java… https://www.cve.org/CVERecord?id=CVE-2025-70963

    Post summary

    CVE-2025-70963 affects Gophish versions <=0.12.1, exposing users’ API keys via the admin dashboard due to incorrect access control. No exploit, patch, or active exploitation is mentioned in the text.

    00010213
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgetgophishgophish---

Explore more