← Volver al buscador de CVEs

CVE-2026-52813

Gogs

Descripción

Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences (../) are accepted by Gogs, and repositories under them are written to paths following these path traversals. This allows storing/retrieving data for repositories at arbitrary locations on the filesystem. By creating nested structure of Git repositories, one can overwrite the other-s hooks configuration to result in Remote Code Execution (RCE). This vulnerability is fixed in 0.14.3.

CVSS 10EPSS 0.922%Riesgo 1.08
Ver fuente
Publicación
2026-06-24 21:16:57
Versiones afectadas
<0.14.3
Tipo
Aplicación web
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H