PT-2026-51459 · Gogs · Gogs
CVE-2026-52801
·
Published
2026-06-23
·
Updated
2026-07-30
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Gogs (affected versions not specified)
Description
An information disclosure issue exists in the Mirror Settings functionality, which allows authenticated users to import local repositories from the server filesystem. This occurs due to a lack of validation in the
SaveAddress() function, bypassing the protections implemented in the New Migration feature. This flaw enables access to any repository the git user has permissions to view and may also lead to blind Server-Side Request Forgery (SSRF), a condition where the server is induced to make requests to an unintended location without returning the response to the attacker.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gogs