PT-2025-26688 · Gogs · Gogs
CVE-2024-56731
·
Published
2025-06-24
·
Updated
2026-08-01
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Gogs versions prior to 0.13.3
Description
An insufficient patch for a previous issue allows unprivileged user accounts to delete files within the
.git directory. This is possible because the system fails to check for symbolic links that point to the .git directory, bypassing existing security checks. Consequently, an attacker can achieve remote command execution with the privileges of the account defined by the RUN USER variable in the configuration. This allows unauthorized access to and modification of code hosted by any user on the same instance.Recommendations
Update Gogs to version 0.13.3.
Exploit
Fix
DoS
RCE
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gogs