
Gogs zero-day opens door to remote code execution on default-config servers
Security researchers warn of a critical zero-day in the Gogs self-hosted Git service that enables remote code execution on internet-facing instances via an argument-injection chain in the Merge() path. The flaw affects current releases (0.14.2, 0.15.0+dev) and can be exploited starting from a registered account on servers with open registration and unlimited repository creation, potentially allowing an attacker to run arbitrary code, access private data, and pivot to other systems. There is no patch or CVE assigned yet; thousands of Gogs servers are exposed online, highlighting the risk. This follows a prior Gogs RCE patch for CVE-2025-8110 and has prompted caution from security agencies.