HarborGuard / CVE
Back to search
CRITICALCVE-2026-25921Published Modified CNA GitHub_M

CVE-2026-25921: Gogs: Cross-repository LFS object overwrite via missing content hash verification

Gogs is an open source self-hosted Git service. Prior to version 0.14.2, overwritable LFS object across different repos leads to supply-chain attack, all LFS objects are vulnerable to be maliciously overwritten by malicious attackers. This issue has been patched in version 0.14.2.

Metrics

CVSS v3.1
9.3
Severity
CRITICAL
Fixed in
Affected Products
1
Affected packages
  • gogs / gogs
    < 0.14.2
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:L