PT-2026-6855 · Go · Github.Com/Gophish/Gophish

Published

2026-02-06

·

Updated

2026-02-06

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U
Gophish <= 0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the rendered HTML/JavaScript of the page on every login. This makes permanent API credentials accessible to any script running in the browser context.

Fix

Improper Access Control

Information Disclosure

Weakness Enumeration

Related Identifiers

GHSA-9F8M-9547-2GQM

Affected Products

Github.Com/Gophish/Gophish