← Retour à la recherche de CVE

CVE-2026-52813

Gogs

Description

Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences (../) are accepted by Gogs, and repositories under them are written to paths following these path traversals. This allows storing/retrieving data for repositories at arbitrary locations on the filesystem. By creating nested structure of Git repositories, one can overwrite the other-s hooks configuration to result in Remote Code Execution (RCE). This vulnerability is fixed in 0.14.3.

CVSS 10EPSS 0.922%Risque 1.08
Voir la source
Publication
2026-06-24 21:16:57
Versions concernées
<0.14.3
Type
Application web
Vecteur
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H