PT-2025-26688 · Gogs · Gogs

Published

2025-06-24

·

Updated

2026-02-12

·

CVE-2024-56731

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gogs versions prior to 0.13.3
Description Gogs, an open-source self-hosted Git service, contains a flaw where unprivileged user accounts can execute arbitrary commands on the Gogs instance. This is due to an insufficient patch for a previous issue, allowing attackers to delete files within the .git directory and achieve remote command execution. The issue stems from a lack of checks for symbolic links, enabling attackers to bypass the intended security measures. Attackers can potentially access and modify any user's code hosted on the same instance, executing commands with the privileges of the account specified by the RUN USER configuration variable.
Recommendations Versions prior to 0.13.3 should be updated to version 0.13.3 or later.

Exploit

Fix

RCE

Files Accessible to External Parties

Weakness Enumeration

Related Identifiers

CVE-2024-56731
GHSA-WJ44-9VCG-WJQ7
GO-2025-3776
OPENSUSE-SU-2025:15405-1

Affected Products

Gogs