Tools AI-Found Vulnerability Register aifv-0029
Register entry
Gogs two-factor bypass via recovery code, disclosed by OpenAI Security Research
- CVE
- CVE-2025-64175
- GHSA
- GHSA-p6x6-9mx6-26wj
- Project
- Gogs
- Component
- two-factor authentication
- Finder
- OpenAI Aardvark
- Autonomy
- agentic security researcher; disclosures filed by OpenAI
- Evidence tier
- CNA credits the finder in its own advisory
- Assigner
- GitHub
- Severity
- 7.7 High (CVSS 3.1)
- Bounty
- None published
- Confidence
- CONFIRMED
What happened
A two-factor bypass in Gogs published 6 February 2026 with GitHub as CNA, whose advisory text names OpenAI Security Research as the discloser.
Credit as recorded: GHSA-p6x6-9mx6-26wj names OpenAI Security Research and [email protected]; the CVE credits array is empty. Date basis: datePublished.
Sources
- CVE record, cvelistV5 mirrorraw.githubusercontent.com/CVEProject/cvelistV5/main/cves/202…
- GitHub advisory GHSA-p6x6-9mx6-26wjgithub.com/advisories/GHSA-p6x6-9mx6-26wj
One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026