CVE-2026-52806

Published
View on NVD ↗
CVSS v3
9.9
CRITICAL
CVSS v2
N/A
Affected
1
PROJECT

Description

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially crafted branch name that injects the --exec flag into the git rebase command during the "Rebase before merging" merge operation. This vulnerability is fixed in 0.14.3.

The painless way to host your own Git service
GitHubGitHub
47.6K