Tag
critical
advisory
Gogs Remote Code Execution via git rebase --exec Argument Injection (GHSA-qf6p-p7ww-cwr9)
1 rule 5 TTPsGogs, a self-hosted Git service, is vulnerable to a Critical (CVSS 9.9) Remote Code Execution (RCE) via `git rebase --exec` argument injection (GHSA-qf6p-p7ww-cwr9) during pull request merge operations, allowing an authenticated attacker to execute arbitrary commands as the Gogs server process user and achieve full server compromise.
Gogs 0.14.2 +2
rce
gogs
git
code-repository
vulnerability
argument-injection
server-side-request-forgery
1r
5t
critical
advisory
Multiple Critical Vulnerabilities in Gogs Allow Remote Code Execution and Data Compromise
7 TTPs 3 CVEs 10 IOCsMultiple critical vulnerabilities in Gogs versions prior to 0.14.3, including remote code execution (RCE) flaws (CVE-2026-52813, CVE-2026-52806) and arbitrary file write capabilities (CVE-2026-52811), enable attackers to achieve full host operating system takeover, steal proprietary source code, and facilitate lateral movement.
PoC
Gogs
rce
path-traversal
command-injection
git
web-application
7t
3c
10i
updated