YFarmX logoYFarmX

Tools AI-Found Vulnerability Register aifv-0030

Register entry

Gogs unauthenticated file upload, disclosed by OpenAI Security Research

CVE
CVE-2026-25242
GHSA
GHSA-fc3h-92p8-h36f
Project
Gogs
Component
file upload
Finder
OpenAI Aardvark
Autonomy
agentic security researcher; disclosures filed by OpenAI
Evidence tier
CNA credits the finder in its own advisory
Assigner
GitHub
Severity
6.9 Medium (CVSS 4.0)
Bounty
None published
Confidence
CONFIRMED

What happened

An unauthenticated file upload in Gogs, advisory published 17 February 2026 and CVE record 19 February, whose disclosure header dates the discovery to 5 August 2025, three months before OpenAI announced Aardvark.

Credit as recorded: GHSA-fc3h-92p8-h36f: "Date: Aug 5, 2025 Discoverer: OpenAI Security Research"; the CVE credits array is empty. Date basis: datePublished.

Sources

One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026