Aikido.Dev
Remote Code Execution Vulnerabilities in Gogs: Recent Developments
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Gogs, an open-source Git hosting platform, has faced multiple Remote Code Execution (RCE) vulnerabilities. The most recent, CVE-2026-52813, was patched in version 0.14.3, released on August 19, 2026, after a history of delayed fixes. This vulnerability allowed path traversal through organization usernames, enabling unauthorized filesystem access. Another vulnerability, CVE-2024-44625, was reported in 2024 but remained unpatched for an extended period, highlighting ongoing security issues within Gogs. Users are advised to migrate to more secure alternatives like Gitea or Forgejo. Despite recent fixes, one bypass vulnerability remains unaddressed. The situation reflects a concerning trend of delayed responses to critical vulnerabilities in Gogs.
Key Points: • CVE-2026-52813 was patched in Gogs 0.14.3 on August 19, 2026. • CVE-2024-44625 remains unpatched, exposing users to significant risks. • Users are recommended to migrate to Gitea or Forgejo for better security.