PT-2026-23488 · Gogs · Gogs
Odgrso
·
Published
2026-02-19
·
Updated
2026-03-25
·
CVE-2026-26276
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Gogs versions prior to 0.14.2
Description
Gogs, a self-hosted Git service, is affected by a DOM-Based Cross-Site Scripting (XSS) issue. An attacker can inject an HTML/JavaScript payload into a repository’s Milestone name. When another user selects this Milestone on the New Issue page (
/issues/new), the malicious script is executed, potentially leading to information theft, CSRF token extraction, and unauthorized repository operations. The impact scope depends on the victim’s permission level. The vulnerable parameter is the Milestone name.Recommendations
Update to version 0.14.2 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gogs