Vulnerabilità · 117 giorni fa
Un'installazione predefinita di Gogs offre a un attaccante l'intera forge, non un singolo repo. Il controllo standard di “only trusted repo owners can rebase” non considera che la registrazione aperta e la creazione di repo consentono a uno sconosciuto di creare il proprio account, quindi raggiungere l'esecuzione di comandi lato server tramite rebase merging.
6 fonti che coprono questa storia
No fix yet for critical RCE bug in open-source Git service Gogs - exploit module is out
Researcher reported the vuln in March. Maintainers haven't responded to his messages since
Gogs Zero-Day Exposes Servers to Remote Code Execution
The critical-severity issue, assigned a CVSS score of 9.4, is an argument injection flaw that can be exploited by authenticated attackers via pull requests with malicious branch names.
Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code
Gogs 9.4 CVSS flaw exploits git rebase injection on 1,141 exposed instances, enabling remote code execution.
Two months after Rapid7 discovered the hole in the Git service, the project maintainer has yet to patch the bug.
Authenticated RCE via Argument Injection in Gogs (NOT FIXED)
Rapid7 researchers found that Gogs allows authenticated users to achieve RCE on the server by creating a pull request with a specially crafted branch name.
New Gogs zero-day flaw lets hackers get remote code execution
An unpatched zero-day vulnerability in the Gogs self-hosted Git service can allow attackers to gain remote code execution (RCE) on Internet-facing instances.
Part of the PlainSec briefing for 2026-05-28