Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5367 articles · 195575 vulns · 37/41 feeds (7d)
← Back to list
9.9
CVE-2026-52806KEVEXPLOITEDPATCHED
gogs · gogs

Gogs: RCE via git rebase --exec argument injection in pull request merge

Description

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially crafted branch name that injects the --exec flag into the git rebase command during the "Rebase before merging" merge operation. This vulnerability is fixed in 0.14.3.

Affected Products

VendorProductVersions
gogsgogsgo/gogs.io/gogs: < 0.14.3

References

  • https://github.com/gogs/gogs/security/advisories/GHSA-qf6p-p7ww-cwr9(x_refsource_CONFIRM)
  • https://github.com/gogs/gogs/pull/8301(x_refsource_MISC)
  • https://github.com/gogs/gogs/commit/a9dbafbfd8e1020bacc626420238c01d75d03364(x_refsource_MISC)
  • https://github.com/gogs/gogs/releases/tag/v0.14.3(x_refsource_MISC)
  • https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-52806.yaml(exploit, nuclei)

Related News (3 articles)

Tier C
VulDB56d ago
CVE-2026-52806 | Gogs up to 0.14.2 command injection (GHSA-qf6p-p7ww-cwr9)
→ No new info (linked only)
Tier B
BSI Advisories62d ago
[NEU] [kritisch] Gogs: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
Rapid7 Blog70d ago
Criminal AI-as-a-Service in 2026: How the Underground Market Is Operationalizing Cybercrime
→ No new info (linked only)
CVSS 3.19.9 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
gogs.io/gogs@0.14.3
CWECWE-77
PublishedJun 23, 2026
Last enriched56d agov2
Tags
GHSA-qf6p-p7ww-cwr9go
Trending Score0
Source articles3
Independent3
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-52813EXPKEV
Gogs: Path Traversal in organization name results in RCE through Git hooks
Trending: 135
HIGHCVE-2026-52810
Gogs: Write to readonly repositories using receive-pack + service=git-upload-pack confusion
Trending: 50
HIGHCVE-2026-52805EXP
Gogs: Migration Redirect Bypass Leads to Internal Repository Theft
HIGHCVE-2026-25119
Gogs: Authentication Bypass via Unvalidated Reverse Proxy Headers
MEDIUMCVE-2026-52802EXP
Gogs: Open Redirect via redirect_to in Gogs

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 23, 2026
Added to CISA KEV
Jun 23, 2026
Discovered by ZDM
Jun 23, 2026
Updated: affectedVersions, severity
Jun 25, 2026
Actively Exploited
Jun 26, 2026
Exploit Available
Jun 26, 2026
Patch Available
Jun 26, 2026

Version History

v2
Last enriched 56d ago
v2Tier C56d ago

Updated affected versions to include 0.14.2, changed severity to HIGH, and noted no available exploit.

affectedVersionsseverity
via VulDB
v158d ago

Initial creation