Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability

Unpatched Gogs Rebase Injection Remote Code Execution Risk

Updated 28.05.2026 17:25
Case score 59
Case score 59 Members 1 Latest activity 28.05.2026 17:25
Members 1 First seen 28.05.2026 17:25 Last seen 28.05.2026 17:25 Updated 28.05.2026 17:25

Overview

An unpatched **Gogs** argument injection flaw in the **Rebase before merging** workflow can give an authenticated, non-admin user remote code execution on self-hosted servers. The issue affects **Gogs 0.14.2** and **0.15.0+dev**, and default deployments with open registration and unrestricted repository creation lower the barrier to reaching the vulnerable path. Public technical details describe server compromise risk, exposure of private repositories and secrets, and potential code tampering. The maintainers had acknowledged the report, but no patch or remediation timeline was available at disclosure time, while more than **2,400** Internet-facing Gogs servers were noted as exposed overall.