Gogs zero-day opens door to remote code execution on default-config servers

Security researchers warn of a critical zero-day in the Gogs self-hosted Git service that enables remote code execution on internet-facing instances via an argument-injection chain in the Merge() path. The flaw affects current releases (0.14.2, 0.15.0+dev) and can be exploited starting from a registered account on servers with open registration and unlimited repository creation, potentially allowing an attacker to run arbitrary code, access private data, and pivot to other systems. There is no patch or CVE assigned yet; thousands of Gogs servers are exposed online, highlighting the risk. This follows a prior Gogs RCE patch for CVE-2025-8110 and has prompted caution from security agencies.
- New Gogs zero-day flaw lets hackers get remote code execution BleepingComputer
- Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code The Hacker News
- Lack of response to critical vulnerability in Gogs is a reminder of the limits of open source projects InfoWorld
- New Gogs 0-Day Vulnerability Lets Attackers Run Malicious Code on the Server Remotely CyberSecurityNews
- Rapid7 warns of unpatched critical-severity zero-day flaw in popular Gogs self-hosted Git service Cyber Daily
Reading Insights
0
35
4 min
vs 5 min read
88%
836 → 104 words
Want the full story? Read the original article
Read on BleepingComputer