PT-2025-26688 · Gogs · Gogs

CVE-2024-56731

·

Published

2025-06-24

·

Updated

2026-08-01

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gogs versions prior to 0.13.3
Description An insufficient patch for a previous issue allows unprivileged user accounts to delete files within the .git directory. This is possible because the system fails to check for symbolic links that point to the .git directory, bypassing existing security checks. Consequently, an attacker can achieve remote command execution with the privileges of the account defined by the RUN USER variable in the configuration. This allows unauthorized access to and modification of code hosted by any user on the same instance.
Recommendations Update Gogs to version 0.13.3.

Exploit

Fix

DoS

RCE

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-56731
GHSA-WJ44-9VCG-WJQ7
GO-2025-3776
OPENSUSE-SU-2025:15405-1

Affected Products

Gogs