Gogs zero-day opens door to remote code execution on default-config servers

1 min read
Source: BleepingComputer
Gogs zero-day opens door to remote code execution on default-config servers
Photo: BleepingComputer
TL;DR Summary

Security researchers warn of a critical zero-day in the Gogs self-hosted Git service that enables remote code execution on internet-facing instances via an argument-injection chain in the Merge() path. The flaw affects current releases (0.14.2, 0.15.0+dev) and can be exploited starting from a registered account on servers with open registration and unlimited repository creation, potentially allowing an attacker to run arbitrary code, access private data, and pivot to other systems. There is no patch or CVE assigned yet; thousands of Gogs servers are exposed online, highlighting the risk. This follows a prior Gogs RCE patch for CVE-2025-8110 and has prompted caution from security agencies.

Share this article

Reading Insights

Total Reads

0

Unique Readers

35

Time Saved

4 min

vs 5 min read

Condensed

88%

836104 words

Want the full story? Read the original article

Read on BleepingComputer