DOM-Based XSS Vulnerability in Gogs Git Service by Gogs
CVE-2026-26276
7.3HIGH
What is CVE-2026-26276?
Gogs is an open-source self-hosted Git service that, prior to version 0.14.2, was susceptible to a DOM-Based Cross-Site Scripting (XSS) attack. An attacker could exploit this vulnerability by storing an HTML/JavaScript payload in a repository's Milestone name. When another user attempted to create a new issue and selected this Milestone, the malicious script would execute in the context of the user's browser. This flaw has been addressed and patched in Gogs version 0.14.2, reinforcing the importance of regularly updating and securing software.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
gogs < 0.14.2
