Home

Description

Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the rendered HTML/JavaScript of the page on every login. This makes permanent API credentials accessible to any script running in the browser context.

PUBLISHED Reserved 2026-01-09 | Published 2026-02-06 | Updated 2026-02-06 | Assigner mitre

References

github.com/gophish/gophish/issues/9366

cve.org (CVE-2025-70963)

nvd.nist.gov (CVE-2025-70963)

Download JSON