← Späť na vyhľadávanie CVE

CVE-2026-52813

Gogs

Popis

Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences (../) are accepted by Gogs, and repositories under them are written to paths following these path traversals. This allows storing/retrieving data for repositories at arbitrary locations on the filesystem. By creating nested structure of Git repositories, one can overwrite the other-s hooks configuration to result in Remote Code Execution (RCE). This vulnerability is fixed in 0.14.3.

CVSS 10EPSS 0.922%Riziko 1.08
Zobraziť zdroj
Zverejnené
2026-06-24 21:16:57
Dotknuté verzie
<0.14.3
Typ
Webová aplikácia
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H