9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, due to the insufficient patch for CVE-2024-56731, it's still possible to update files in the .git directory and achieve remote command execution. This issue has been patched in versions 0.13.4 and 0.14.0+dev.
AI Analysis
Remote command execution vulnerability in Gogs due to insufficient patch for CVE-2024-56731
Basic Information
ID
CVE-2025-64111
Source
GitHub_M
Published
Feb 6, 2026 at 16:58
Affected Product
Vendor
gogs
Product
gogs
Version
< 0.14.0+dev
Affected Versions
gogs gogs < 0.14.0+dev
gogs gogs < 0.13.4
gogs gogs < 0.13.4
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
Gogs
Product
Gogs
Version
0.13.3 and prior