Remote Code Execution Vulnerability in Gogs by Gogs
CVE-2026-52806
9.9CRITICAL
What is CVE-2026-52806?
Gogs, an open source self-hosted Git service, has a vulnerability that allows authenticated users to execute remote code on the server. This occurs when a specially crafted pull request is made, containing a branch name that injects the --exec flag into the git rebase command during the 'Rebase before merging' operation. This critical flaw impacts the performance and security of Gogs installations prior to version 0.14.3. Users are encouraged to upgrade to version 0.14.3 or later for a fix.
Affected Version(s)
gogs < 0.14.3
References
EPSS Score
7% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
