Cross-Account Vulnerability in Gogs Git Service
CVE-2025-64175
What is CVE-2025-64175?
Gogs, the open-source self-hosted Git service, has a significant vulnerability in its 2FA recovery code validation. In versions up to 0.13.3, the system fails to scope recovery codes by individual users, creating a loophole where an attacker can bypass two-factor authentication (2FA). If they acquire a victim's username and password, they may use any unused recovery code from their own account to gain unauthorized access to the victim’s account. This flaw allows full account takeover, rendering 2FA ineffective. The issue has been addressed in versions 0.13.4 and 0.14.0+dev.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
gogs < 0.14.0+dev < 0.14.0+dev
gogs < 0.13.4 < 0.13.4
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
