Unpatched Gogs Rebase Injection Remote Code Execution Risk
Case
Updated: 28.05.2026 17:25
· First: 28.05.2026 17:25
· 📰 0 src / 1 articles
An unpatched Gogs argument injection flaw in the Rebase before merging workflow can give an authenticated, non-admin user remote code execution on self-hosted servers. The issue affects Gogs 0.14.2 and 0.15.0+dev, and default deployments with open registration and unrestricted repository creation lower the barrier to reaching the vulnerable path. Public technical details describe server compromise risk, exposure of private repositories and secrets, and potential code tampering. The maintainers had acknowledged the report, but no patch or remediation timeline was available at disclosure time, while more than 2,400 Internet-facing Gogs servers were noted as exposed overall.