CVE 10 CRITICAL

Gogs: Path Traversal in organization name results in RCE through Git hooks_CVE-2026-52813

10 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Description

Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences (../) are accepted by Gogs, and repositories under them are written to paths following these path traversals. This allows storing/retrieving data for repositories at arbitrary locations on the filesystem. By creating nested structure of Git repositories, one can overwrite the other's hooks configuration to result in Remote Code Execution (RCE). This vulnerability is fixed in 0.14.3.

AI Analysis

Path traversal vulnerability in Gogs organization name, allowing Remote Code Execution (RCE) through Git hooks

Basic Information

ID CVE-2026-52813
Source GitHub_M
Published Jun 24, 2026 at 20:33

Affected Product

Vendor gogs
Product gogs
Version < 0.14.3
Affected Versions gogs gogs < 0.14.3

CWE Classification

AI Assessment

AI Score 10 / 10
AI Severity Critical
Vendor Gogs
Product Gogs
Version < 0.14.3

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.