logo

No fix yet for critical RCE bug in open-source Git service Gogs - exploit module is out

ID: 435f6a85-4d7d-5730-865d-f23d3841a728

STIX ID: report--435f6a85-4d7d-5730-865d-f23d3841a728

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

...
...

A critical RCE vulnerability (reported CVSS 9.4) in Gogs allows authenticated users to inject arguments into the git rebase command during pull-request merges (when "Rebase before merging" is enabled), enabling arbitrary code execution across Windows, Linux, and macOS installations. The maintainers have not released a patch, a Metasploit module is public, and recommended mitigations include disabling user registration, restricting repository creation, and disabling rebase merges until a fix is available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.