AI description
CVE-2026-52813 is a path traversal vulnerability found in Gogs, an open-source self-hosted Git service, affecting all versions prior to 0.14.3. The flaw stems from Gogs accepting organization names that contain path traversal sequences (e.g., "../"), which are then used to construct filesystem paths without proper sanitization. This vulnerability allows an attacker to store or retrieve repository data at arbitrary locations on the filesystem. By creating a nested structure of Git repositories, an attacker can overwrite the Git hooks configuration of another repository, ultimately leading to Remote Code Execution (RCE).
- Description
- Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences (../) are accepted by Gogs, and repositories under them are written to paths following these path traversals. This allows storing/retrieving data for repositories at arbitrary locations on the filesystem. By creating nested structure of Git repositories, one can overwrite the other's hooks configuration to result in Remote Code Execution (RCE). This vulnerability is fixed in 0.14.3.
- Source
- security-advisories@github.com
- NVD status
- Deferred
CVSS 3.1
- Type
- Secondary
- Base score
- 10
- Impact score
- 6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- security-advisories@github.com
- CWE-23
- Hype score
- Not currently trending
CVE-2026-52813 & CVE-2026-52806 & CVE-2026-52811: Three RCE vulnerabilities in gogs, up to 10.0 rating 🔥 Recently disclosed vulnerabilities in gogs allow an attacker to execute arbitrary code. PoC exist for all three! 👉 https://t.co/PN3cJIwCW5 https://t.co/MUJWMlh
@Netlas_io
27 Jun 2026
1471 Impressions
3 Retweets
22 Likes
4 Bookmarks
0 Replies
0 Quotes
Gogsで重大(Critical)な脆弱性3件が修正。最高CVSSスコア10。遠隔コード実行可能なパストラバーサルCVE-2026-52813、rebase引数インジェクションCVE-2026-52806、シンボリックリンクリンクを用いたファイル書き込みCVE-2026-
@__kokumoto
26 Jun 2026
609 Impressions
0 Retweets
0 Likes
2 Bookmarks
0 Replies
0 Quotes
Warning: Multiple Critical Vulnerabilities in #Gogs. CVE-2026-52813, CVE-2026-52806 & CVE-2026-52811, max CVSS: 10.0. These flaws can lead to remote code execution #RCE! #Patch #Patch #Patch More info: https://t.co/VkhJfsDYIB
@CCBalert
25 Jun 2026
291 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes