Gogs Vulnerability Allows Remote Code Execution via Path Traversal

Gogs Vulnerability Allows Remote Code Execution via Path Traversal

1h ago Feedlyadvisories.gitlab.comosv.devvulners.com 83% similarity 72.0
Share:

Article Content

Browse articles
ThreatCluster

Gogs, a self-hosted Git service, has a vulnerability allowing path traversal in organization names. This flaw permits attackers to create nested Git repositories, leading to the potential for Remote Code Execution (RCE) by overwriting hooks configurations. The issue arises from unsanitized organization names during repository creation, allowing paths like ../../../../tmp/test to be used. This vulnerability affects all versions of Gogs prior to 0.14.3. The CVE-2026-52813 has been assigned to this vulnerability, highlighting its severity. Security advisories have been issued, and users are urged to update their installations. The flaw emphasizes the need for proper input sanitization in web applications.

Key Points: • Gogs allows path traversal in organization names, leading to RCE. • Unsanitized input during repository creation enables arbitrary filesystem access. • Users are advised to upgrade to Gogs version 0.14.3 or later to mitigate risks.

ThreatCluster AI

Timeline

2026-06-24
CVE-2026-52813 published
Gogs vulnerability allows path traversal in organization names, leading to RCE. Affected versions are prior to 0.14.3.
osv.dev
2026-06-24
Security advisory released
GitHub Advisories released a security advisory regarding the Gogs vulnerability, urging users to update.
Feedly
2026-06-24
Gogs vulnerability confirmed
The vulnerability was confirmed by multiple sources, detailing the exploit method and impact on users.
advisories.gitlab.com

Community

Browse all →