← Vulnerability feed

Vulnerability record · CVE-2025-70963 · published 6 February 2026

CVE-2025-70963: Getgophish gophish information exposure vulnerability

Getgophish · Gophish

Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the rendered HTML/JavaScript of the page on every login. This makes permanent API credentials accessible to any script running in the browser context.

7.6 CVSS 3.1 High EPSS 0.28% · top 81.3% CWE-200 · Information exposureCWE-922 · CWE-922
7.6CVSS 3.1 base score
0.28%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the rendered HTML/JavaScript of the page on every login. This makes permanent API credentials accessible to any script running in the browser context.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/gophish/gophish/issues/9366 ExploitIssue TrackingVendor Advisory

Track CVE-2025-70963 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2020-24707Getgophish gophish csv injection vulnerabilityGophish before 0.11.0 allows the creation of CSV sheets that contain malicious content.EPSS 1.3%7.5CVE-2022-45003Getgophish gophish uncontrolled resource consumption vulnerabilityGophish through 0.12.1 allows attackers to cause a Denial of Service (DoS) via a crafted payload involving autofocus.EPSS 1.0%7.5CVE-2020-24713Getgophish gophish insufficient session expiration vulnerabilityGophish through 0.10.1 does not invalidate the gophish cookie upon logout.EPSS 1.2%6.5CVE-2020-24711Getgophish gophish clickjacking vulnerabilityThe Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via a clickjacking attackEPSS 1.6%6.1CVE-2024-2211Getgophish gophish cross-site scripting vulnerabilityCross-Site Scripting stored vulnerability in Gophish affecting version 0.12.1. This vulnerability could allow an attacker to store a malicious JavaSc…EPSS 0.29%6.1CVE-2022-45004Getgophish gophish cross-site scripting vulnerabilityGophish through 0.12.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted landing page.EPSS 0.60%5.4CVE-2022-25295Getgophish gophish open redirect vulnerabilityThis affects the package github.com/gophish/gophish before 0.12.0. The Open Redirect vulnerability exists in the next query parameter. The applicatio…EPSS 0.67%5.4CVE-2020-24708Getgophish gophish cross-site scripting vulnerabilityCross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the Host field on the send profile form.EPSS 0.63%

Source: NIST National Vulnerability Database (record CVE-2025-70963), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.