No fix yet for critical RCE bug in open-source Git service Gogs - exploit module is out
ID: 435f6a85-4d7d-5730-865d-f23d3841a728
STIX ID: report--435f6a85-4d7d-5730-865d-f23d3841a728
Feed Name: The Register (Security)
A critical RCE vulnerability (reported CVSS 9.4) in Gogs allows authenticated users to inject arguments into the git rebase command during pull-request merges (when "Rebase before merging" is enabled), enabling arbitrary code execution across Windows, Linux, and macOS installations. The maintainers have not released a patch, a Metasploit module is public, and recommended mitigations include disabling user registration, restricting repository creation, and disabling rebase merges until a fix is available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
