Remote Code Execution Vulnerability in Gogs by Gogs
CVE-2026-52806
9.9CRITICAL
What is CVE-2026-52806?
Gogs, an open source self-hosted Git service, has a vulnerability that allows authenticated users to execute remote code on the server. This occurs when a specially crafted pull request is made, containing a branch name that injects the --exec flag into the git rebase command during the 'Rebase before merging' operation. This critical flaw impacts the performance and security of Gogs installations prior to version 0.14.3. Users are encouraged to upgrade to version 0.14.3 or later for a fix.
Affected Version(s)
gogs < 0.14.3
