Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. gogs.io/gogs
  4. ›
  5. CVE-2026-52813

CVE-2026-52813: Gogs has Path Traversal in organization name that results in RCE through Git hooks

June 23, 2026

Organization names containing path traversal sequences (../) are accepted by Gogs, and repositories under them are written to paths following these path traversals. This allows storing/retrieving data for repositories at arbitrary locations on the filesystem. By creating nested structure of Git repositories, one can overwrite the other’s hooks configuration to result in Remote Code Execution (RCE).

References

  • github.com/advisories/GHSA-c39w-43gm-34h5
  • github.com/gogs/gogs/commit/f6acd467305943aae8403cbac81f0118dd1235d7
  • github.com/gogs/gogs/pull/8334
  • github.com/gogs/gogs/releases/tag/v0.14.3
  • github.com/gogs/gogs/security/advisories/GHSA-c39w-43gm-34h5
  • nvd.nist.gov/vuln/detail/CVE-2026-52813

Code Behaviors & Features

Detect and mitigate CVE-2026-52813 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.14.3

Fixed versions

  • 0.14.3

Solution

Upgrade to version 0.14.3 or above.

Impact 10 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-23: Relative Path Traversal

Source file

go/gogs.io/gogs/CVE-2026-52813.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Mon, 13 Jul 2026 12:19:49 +0000.