Cross-Account Vulnerability in Gogs Git Service
CVE-2025-64175
7.7HIGH
What is CVE-2025-64175?
Gogs, the open-source self-hosted Git service, has a significant vulnerability in its 2FA recovery code validation. In versions up to 0.13.3, the system fails to scope recovery codes by individual users, creating a loophole where an attacker can bypass two-factor authentication (2FA). If they acquire a victim's username and password, they may use any unused recovery code from their own account to gain unauthorized access to the victim’s account. This flaw allows full account takeover, rendering 2FA ineffective. The issue has been addressed in versions 0.13.4 and 0.14.0+dev.
Affected Version(s)
gogs < 0.14.0+dev < 0.14.0+dev
gogs < 0.13.4 < 0.13.4
