G
ogs is an open source self-hosted Git service. Prior to version 0.14.2, overwritable LFS object across different repos leads to supply-chain attack, all LFS objects are vulnerable to be maliciously overwritten by malicious attackers. This issue has been patched in version 0.14.2.
References
Configurations
No configuration.
History
05 Mar 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-05 19:16
Updated : 2026-03-05 19:38
NVD link : CVE-2026-25921
Mitre link : CVE-2026-25921
CVE.ORG link : CVE-2026-25921
JSON object : View
Products Affected
No product.
CWE
CWE-345
Insufficient Verification of Data Authenticity