Tools AI-Found Vulnerability Register aifv-0030
Register entry
Gogs unauthenticated file upload, disclosed by OpenAI Security Research
- CVE
- CVE-2026-25242
- GHSA
- GHSA-fc3h-92p8-h36f
- Project
- Gogs
- Component
- file upload
- Finder
- OpenAI Aardvark
- Autonomy
- agentic security researcher; disclosures filed by OpenAI
- Evidence tier
- CNA credits the finder in its own advisory
- Assigner
- GitHub
- Severity
- 6.9 Medium (CVSS 4.0)
- Bounty
- None published
- Confidence
- CONFIRMED
What happened
An unauthenticated file upload in Gogs, advisory published 17 February 2026 and CVE record 19 February, whose disclosure header dates the discovery to 5 August 2025, three months before OpenAI announced Aardvark.
Credit as recorded: GHSA-fc3h-92p8-h36f: "Date: Aug 5, 2025 Discoverer: OpenAI Security Research"; the CVE credits array is empty. Date basis: datePublished.
Sources
- CVE record, cvelistV5 mirrorraw.githubusercontent.com/CVEProject/cvelistV5/main/cves/202…
- GitHub advisory GHSA-fc3h-92p8-h36fgithub.com/advisories/GHSA-fc3h-92p8-h36f
One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026