← Zurück zur CVE-Suche

CVE-2026-52813

Gogs

Beschreibung

Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences (../) are accepted by Gogs, and repositories under them are written to paths following these path traversals. This allows storing/retrieving data for repositories at arbitrary locations on the filesystem. By creating nested structure of Git repositories, one can overwrite the other-s hooks configuration to result in Remote Code Execution (RCE). This vulnerability is fixed in 0.14.3.

CVSS 10EPSS 0.922%Risiko 1.08
Quelle öffnen
Veröffentlicht
2026-06-24 21:16:57
Betroffene Versionen
<0.14.3
Typ
Webanwendung
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H