Gist: A critical OS command injection (CVE-2025-64111) in Gogs up to 0.13.3 lets attackers inject malicious .git/config via a symlink and repository PUT API, enabling remote code execution and bypassing two-factor authentication.
Signal reason: User/alert reports severe product security failure and exploit.
