Gogs Vulnerability: Authenticated Attackers Can Execute Code via Argument Injection (heise.de)
0xBASE INTEL BRIEF
- Critical RCE vulnerability in Gogs
- Requires authentication; default registration enabled
- No patch available; configuration workaround advised
"A critical vulnerability in the self-hosted Git service Gogs allows authenticated attackers to execute arbitrary code through argument injection in the rebase-before-merge operation. Default settings permit self-registration, enabling attackers to create accounts. No patch is available; developers were contacted in March 2026. Workaround: disable registration and limit repository creation."
no comments yet.