AI description
CVE-2026-52806 is a Remote Code Execution (RCE) vulnerability affecting Gogs, an open-source self-hosted Git service. This flaw allows authenticated users to execute arbitrary commands on the server. The vulnerability stems from improper input sanitization within the `Merge` function in Gogs, specifically when handling the `git rebase` command during a "Rebase before merging" operation. An attacker can craft a pull request with a specially designed branch name that injects the `--exec` flag into the `git rebase` command, leading to the execution of arbitrary shell commands on the Gogs server. This issue has been addressed in Gogs version 0.14.3.
- Description
- Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially crafted branch name that injects the --exec flag into the git rebase command during the "Rebase before merging" merge operation. This vulnerability is fixed in 0.14.3.
- Source
- security-advisories@github.com
- NVD status
- Deferred
CVSS 3.1
- Type
- Secondary
- Base score
- 9.9
- Impact score
- 6
- Exploitability score
- 3.1
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- security-advisories@github.com
- CWE-77
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
4
CVE-2026-52813 & CVE-2026-52806 & CVE-2026-52811: Three RCE vulnerabilities in gogs, up to 10.0 rating 🔥 Recently disclosed vulnerabilities in gogs allow an attacker to execute arbitrary code. PoC exist for all three! 👉 https://t.co/PN3cJIwCW5 https://t.co/MUJWMlh
@Netlas_io
27 Jun 2026
1274 Impressions
3 Retweets
21 Likes
4 Bookmarks
0 Replies
0 Quotes
Gogsで重大(Critical)な脆弱性3件が修正。最高CVSSスコア10。遠隔コード実行可能なパストラバーサルCVE-2026-52813、rebase引数インジェクションCVE-2026-52806、シンボリックリンクリンクを用いたファイル書き込みCVE-2026-
@__kokumoto
26 Jun 2026
609 Impressions
0 Retweets
0 Likes
2 Bookmarks
0 Replies
0 Quotes
Warning: Multiple Critical Vulnerabilities in #Gogs. CVE-2026-52813, CVE-2026-52806 & CVE-2026-52811, max CVSS: 10.0. These flaws can lead to remote code execution #RCE! #Patch #Patch #Patch More info: https://t.co/VkhJfsDYIB
@CCBalert
25 Jun 2026
291 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes