GoYou Cybersecurity (EN)

Critical RCE Vulnerability in Gogs: Remote Code Execution via Malicious Pull Requests

7 min · 29. mai 2026
episode Critical RCE Vulnerability in Gogs: Remote Code Execution via Malicious Pull Requests cover

Beskrivelse

A critical argument injection vulnerability in Gogs, a popular open-source self-hosted Git service, allows authenticated users to achieve remote code execution (RCE) on the server. The exploit involves creating a pull request with a malicious branch name that injects the --exec flag into git rebase during the merge operation. This vulnerability, scored as CVSSv4 9.4 (Critical), enables attackers to compromise the server, read every repository, dump credentials, pivot to other systems, and modify hosted repository code. The vulnerability affects Gogs versions 0.14.2 and 0.15.0+dev, with no patch available at the time of publication. Leggi su GoYou [https://www.goyou.it/en/cybersecurity/2026/05/29/critical-rce-vulnerability-in-gogs-remote-code-execution-via-malicious-pull.html]

Kommentarer

0

Vær den første til å kommentere

Registrer deg nå og bli medlem av GoYou Cybersecurity (EN) sitt community!

Prøv gratis

Prøv gratis i 14 dager

99 kr / Måned etter prøveperioden. · Avslutt når som helst.

  • Eksklusive podkaster
  • 20 timer lydbøker i måneden
  • Gratis podkaster

Alle episoder

300 Episoder