Remote Code Execution Vulnerabilities in Gogs: Recent Developments

Remote Code Execution Vulnerabilities in Gogs: Recent Developments

First seen 19 Aug 2026, 19:39 UTC Aikido.Devfysac.github.iowww.sonarsource.com 87% similarity 57.8

Article Content

Browse articles
ThreatCluster

Gogs, an open-source Git hosting platform, has faced multiple Remote Code Execution (RCE) vulnerabilities. The most recent, CVE-2026-52813, was patched in version 0.14.3, released on August 19, 2026, after a history of delayed fixes. This vulnerability allowed path traversal through organization usernames, enabling unauthorized filesystem access. Another vulnerability, CVE-2024-44625, was reported in 2024 but remained unpatched for an extended period, highlighting ongoing security issues within Gogs. Users are advised to migrate to more secure alternatives like Gitea or Forgejo. Despite recent fixes, one bypass vulnerability remains unaddressed. The situation reflects a concerning trend of delayed responses to critical vulnerabilities in Gogs.

Key Points: • CVE-2026-52813 was patched in Gogs 0.14.3 on August 19, 2026. • CVE-2024-44625 remains unpatched, exposing users to significant risks. • Users are recommended to migrate to Gitea or Forgejo for better security.

ThreatCluster AI How this analysis works

Timeline

2024-11-15
CVE-2024-44625 published
A symbolic link path traversal vulnerability in Gogs was disclosed, allowing RCE.
fysac.github.io
2026-06-24
CVE-2026-52810 and CVE-2026-52813 published
Two vulnerabilities in Gogs were disclosed, including RCE and logic bugs.
Aikido.Dev
2026-07-02
First public PoC for CVE-2026-52813
A proof-of-concept exploit for the RCE vulnerability was released, demonstrating its impact.
Aikido.Dev
2026-08-19
Gogs 0.14.3 released
Version 0.14.3 was released, addressing CVE-2026-52813, but one bypass vulnerability remains.
Aikido.Dev

Community

Browse all →

Tracked Entities in This Story