CVE-2025-64111: Gogs's update .git/config file allows remote command execution
Due to the insufficient patch for the https://github.com/gogs/gogs/security/advisories/GHSA-wj44-9vcg-wjq7, it’s still possible to update files in the .git directory and achieve remote command execution.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-64111 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →