CVE-2026-52804
Published
CVSS v3
N/A
CVSS v2
N/A
Affected
1
PROJECT
Description
Gogs is an open source self-hosted Git service. Prior to 0.14.3, a repository admin collaborator can escalate their privileges to owner-level access by exploiting an off-by-one error in the ChangeCollaborationAccessMode function. This vulnerability is fixed in 0.14.3.