PT-2023-9826 · Gogs+1 · Gogs+1

·

CVE-2024-54148

·

Published

2023-10-27

·

Updated

2025-12-15

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gogs versions prior to 0.13.1
Description The issue is related to errors in handling symbolic links in the Gogs self-hosted Git service. A malicious user can commit and edit a crafted symlink file to a repository, allowing them to gain SSH access to the server.
Recommendations For versions prior to 0.13.1, upgrade to version 0.13.1 or later to protect the server. As a temporary workaround, consider granting access only to trusted users to the Gogs instance on affected versions.

Exploit

Fix

Path traversal

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00102
CVE-2024-54148
GHSA-R7J8-5H9C-F6FX
GO-2024-3355
OPENSUSE-SU-2025:14624-1
OPENSUSE-SU-2025_0060-1
SUSE-SU-2025:0060-1

Affected Products

Gogs
Suse