Critical severityNVD Advisory· Published Feb 6, 2026· Updated Feb 26, 2026
Gogs's update .git/config file allows remote command execution
CVE-2025-64111
Description
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, due to the insufficient patch for CVE-2024-56731, it's still possible to update files in the .git directory and achieve remote command execution. This issue has been patched in versions 0.13.4 and 0.14.0+dev.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
gogs.io/gogsGo | < 0.13.4 | 0.13.4 |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-gg64-xxr9-qhjpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-64111ghsaADVISORY
- github.com/gogs/gogs/blob/d940e692ec58abd45e648c054d7dfd88909034ec/internal/route/api/v1/repo/contents.goghsaWEB
- github.com/gogs/gogs/security/advisories/GHSA-gg64-xxr9-qhjpghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.