CVE-2026-25921

Published
View on NVD ↗
CVSS v3
9.3
CRITICAL
CVSS v2
N/A
Affected
1
PROJECT

Description

Gogs is an open source self-hosted Git service. Prior to version 0.14.2, overwritable LFS object across different repos leads to supply-chain attack, all LFS objects are vulnerable to be maliciously overwritten by malicious attackers. This issue has been patched in version 0.14.2.

The painless way to host your own Git service
GitHubGitHub
47.6K