PT-2026-23488 · Gogs · Gogs

Odgrso

·

Published

2026-02-19

·

Updated

2026-03-25

·

CVE-2026-26276

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Gogs versions prior to 0.14.2
Description Gogs, a self-hosted Git service, is affected by a DOM-Based Cross-Site Scripting (XSS) issue. An attacker can inject an HTML/JavaScript payload into a repository’s Milestone name. When another user selects this Milestone on the New Issue page (/issues/new), the malicious script is executed, potentially leading to information theft, CSRF token extraction, and unauthorized repository operations. The impact scope depends on the victim’s permission level. The vulnerable parameter is the Milestone name.
Recommendations Update to version 0.14.2 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06149
CVE-2026-26276
GHSA-VGJM-2CPF-4G7C
GO-2026-4627
SUSE-SU-2026:1042-1

Affected Products

Gogs