NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #243 by repository stars
Last release 2 years ago
no release in 18 months
Ships unpredictably
gaps range from 9 days to 12 months
Most releases are documented
notes for 9 of 15 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
815 releases · first in 2013
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
We're excited to announce the release of Gophish v0.12.1. This is a minor release that includes a couple of bug fixes and one great new feature.
We're excited to announce the release of Gophish v0.12.1. This is a minor release that includes a couple of bug fixes and one great new feature.
We've added the ability to set trusted_origins in the config.json file. This allows you to add addresses that you expect incoming connections to come from, which is helpful in cases where TLS termination is handled by a load balancer upstream, rather than the application itself. This has been a long discussed and requested feature so it's great to have! Thanks to @mcab and everyone else in this thread.
Our Continuous Integration workflow has been updated and is succeeding again. We've also updated the Release workflow, mitigating some security concerns and adapting it be able to build Windows releases again. These are (hopefully!) at the bottom of this post.
Some JavaScript files hadn't been minified properly, causing problems with adding customer headers. A small bug was fixed where copying a campaign would not show [Deleted] in an edge case - see #2482. Thanks @29vivek.
You can find the full changelog for this release here.
To upgrade, download the release for your platform, extract into a folder, and copy (remember to copy, not move so that you have a backup) your existing gophish.db file into the new directory. Then, run the new Gophish binary and you'll be good to go!
Now, one more thing:
Have questions, comments, or feature ideas about Gophish? Let us know by filing an issue.
| SHA256 Hash | Filename |
|---|---|
| 9ed2f88d6582b798a3448fb51080ff782b40cec8fb4855895720e9f782f68511 | gophish-v0.12.1-linux-32bit.zip |
| 44f598c1eeb72c3b08fa73d57049022d96cea2872283b87a73d21af78a2c6d47 | gophish-v0.12.1-linux-64bit.zip |
| f80786dcb2c4037d7f9d6c9e8e8655c5eeaa8e46ef4032bda704b9ce18e23491 | gophish-v0.12.1-osx-64bit.zip |
| e6936b8a472c730dcb0da64024d82341806869af666fad10f8639e7f85b1b7e6 | gophish-v0.12.1-windows-64bit.zip |
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
We're excited to announce the release of Gophish v0.12.0. This release includes important security fixes, adds some features, and fixes some bugs.
We're excited to announce the release of Gophish v0.12.0. This release includes important security fixes, adds some features, and fixes some bugs.
This has been a long time requested feature, and we're super excited to release it! We've added the ability to add gophish variables to a number of file types which can be attached to emails. As a trivial example it is possible to include Hello {{.FirstName}}, please click here: {{.URL}} to a Word document, or with a little more effort add tracking pixels to documents. This will allow notification of when users have opened attached files, or enabled macros in Office documents. We currently support the following file extensions: docx, docm, pptx, xlsx, xlsm, txt, html, ics. Please see the documentation for more guidance and examples.
Images in emails are now marked as embedded rather than attached, so email clients don't show them as attachments. This is a great addition to improve the quality of campaigns. Thanks @dzsibi
We've added the ability to specify an envelope sender in templates. If left empty, it will fallback to the SMTP-From in the Sender-settings. This can be used to pass SPF-checks but still send a spoofing email. Thanks @ChessSpider and @ptitdoc
Added minor functionality to display last login time for each user in the User Management page and the ability to lock user accounts.
Fixed a minor Open Redirect issue. Thanks @Kirill89
You can find the full changelog for this release here.
To upgrade, download the release for your platform, extract into a folder, and copy (remember to copy, not move so that you have a backup) your existing gophish.db file into the new directory. Then, run the new Gophish binary and you'll be good to go!
Now, one more thing:
Have questions, comments, or feature ideas about Gophish? Let us know by filing an issue.
| SHA256 Hash | Filename |
|---|---|
| 42f228158e91e2fce182fbd60a6669fcbed21f76186563f264a941efbc9c1159 | gophish-v0.12.0-linux-64bit.zip |
| d06945497f0f3467748c50e518aa4e526e8c71cd7fa58c23541cb65477539306 | gophish-v0.12.0-osx-64bit.zip |
| c0fdc4a980914893a9d19544bb6233586db8d81a139657e9773ca8e03c387a02 | gophish-v0.12.0-windows-64bit.zip |
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
We're excited to announce the release of Gophish v0.11.0. This release includes important security fixes, adds some minor features, and fixes some bug…
We're excited to announce the release of Gophish v0.11.0. This release includes important security fixes, adds some minor features, and fixes some bugs.
This release addresses multiple security issues that were identified and reported by the community. As always, we encourage sending in security reports via our security policy, and are appreciative of all the work that went in to finding and reporting these vulnerabilities.
The following vulnerabilities were fixed in this latest release:
Reported by: Marcus Nilsson of usd AG
Reported by: @dunderhay in #1908
An authenticated user could use certain features of Gophish to make inbound connections to the local network. The most critical of these is via the Landing Page import feature, which could be used to make arbitrary upstream web requests.
Since importing local webpages, or otherwise making local network connections (e.g. for SMTP/IMAP servers, webhook URLs, etc.) is an expected use case for Gophish we've decided to implement an opt-in allowlist. By default, we block access only to known IP addresses commonly associated with cloud metadata services, but it is now possible to explicitly set the allowed_internal_hosts configuration variable in the admin_server section of config.json to a list of allowed internal addresses.
More information can be found here.
Reported By: Marcus Nilsson of usd AG
Reported By: @dunderhay in #1901
Various cross-site scripting issues were identified and fixed. All issues required authenticated access and only affected either the user that created the objects, or an administrator using our "Impersonate" issue to impersonate the user that created the objects.
More information can be found in 4e9b94b and 19ef924.
Reported By: Marcus Nilsson of usd AG
Malicious data could be submitted during a campaign that, when exported as a CSV and opened in a spreadsheet viewer, is interpreted as a formula leading to command execution.
More information on CSV Injection can be found here. More information about the fix can be found in b25f5ac.
Reported By: Marcus Nilsson of usd AG
An attacker could create an iframe which tricks an authenticated administrator into unexpectedly clicking the "Reset" button in the settings page, causing their API key to be reset, potentially causing a denial of service condition.
More information about the fix can be found in 6df62e8.
This release adds a basic password policy for administrators, and removes the default password "gophish". Instead, an initial password is randomly generated and printed in the terminal when Gophish is launched for the first time.
It is possible to override the initial password and API key with environment variables if needed.
This release adds the ability to mark emails as reported that were sent as an attachment. Additionally, it changes the underlying IMAP library to be more robust, eliminating some possible bugs.
Credit to @glennzw for the changes!
You can find the full changelog for this release here.
To upgrade, download the release for your platform, extract into a folder, and copy (remember to copy, not move so that you have a backup) your existing gophish.db file into the new directory. Then, run the new Gophish binary and you'll be good to go!
Now, one more thing:
Have questions, comments, or feature ideas about Gophish? Let us know by filing an issue.
| SHA256 Hash | Filename |
|---|---|
| beb32e243e888f21849d3ee09a979a33cd1da7a7cd79438c8f56fce1a2d9d44c | gophish-v0.11.0-linux-32bit.zip |
| f33ac7695850132c04d190f83ef54732421a8d4578be1475d3a819fe6173c462 | gophish-v0.11.0-linux-64bit.zip |
| f1af96033c946ed2fe757b9b3a7aefc63ec3548f0ab21f01c44d70a58410ffbe | gophish-v0.11.0-osx-64bit.zip |
| f5083bc084715319a4e671bc58dc28f66828fec78a43bd41456373fcc024703c | gophish-v0.11.0-windows-64bit.zip |
Your coding agent can read these notes before it upgrades. Set up the MCP server →