CVE-2025-70963: Infoleak
Gophish <= 0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the rendered HTML/JavaScript of the page on every login. This makes permanent API credentials accessible to any script running in the browser context.
Other sources
Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the rendered HTML/JavaScript of the page on every login. This makes permanent API credentials accessible to any script running in the browser context.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-70963?
CVE-2025-70963 is classified as a high severity vulnerability due to incorrect access control leading to exposure of sensitive API keys.
How do I fix CVE-2025-70963?
To fix CVE-2025-70963, upgrade Gophish to version 0.12.2 or later, where this vulnerability has been addressed.
What versions of Gophish are affected by CVE-2025-70963?
Gophish versions up to and including 0.12.1 are affected by CVE-2025-70963.
What impact does CVE-2025-70963 have on Gophish?
CVE-2025-70963 allows unauthorized access to long-lived API keys, potentially compromising user accounts and administrative functions.
Is CVE-2025-70963 a common vulnerability?
CVE-2025-70963 represents a common type of vulnerability where sensitive information is exposed due to improper handling of access controls.