PT-2025-26688 · Gogs · Gogs
Published
2025-06-24
·
Updated
2026-02-12
·
CVE-2024-56731
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Gogs versions prior to 0.13.3
Description
Gogs, an open-source self-hosted Git service, contains a flaw where unprivileged user accounts can execute arbitrary commands on the Gogs instance. This is due to an insufficient patch for a previous issue, allowing attackers to delete files within the
.git directory and achieve remote command execution. The issue stems from a lack of checks for symbolic links, enabling attackers to bypass the intended security measures. Attackers can potentially access and modify any user's code hosted on the same instance, executing commands with the privileges of the account specified by the RUN USER configuration variable.Recommendations
Versions prior to 0.13.3 should be updated to version 0.13.3 or later.
Exploit
Fix
RCE
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gogs