CVE 9.9 CRITICAL

Gogs: RCE via git rebase –exec argument injection in pull request merge_CVE-2026-52806

9.9 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially crafted branch name that injects the --exec flag into the git rebase command during the "Rebase before merging" merge operation. This vulnerability is fixed in 0.14.3.

AI Analysis

Remote Code Execution (RCE) via git rebase --exec argument injection in pull request merge

Basic Information

ID CVE-2026-52806
Source GitHub_M
Published Jun 24, 2026 at 20:21

Affected Product

Vendor gogs
Product gogs
Version < 0.14.3
Affected Versions gogs gogs < 0.14.3

CWE Classification

AI Assessment

AI Score 9.9 / 10
AI Severity Critical
Vendor Gogs
Product Gogs
Version < 0.14.3

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.