logo

New Gogs 0-Day Flaw Enables Remote Code Execution on Servers

ID: 6b82a214-99d4-59f8-93e3-b279e22cfe03

STIX ID: report--6b82a214-99d4-59f8-93e3-b279e22cfe03

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: Divya

...
...

A critical (CVSS v4 9.4) zero-day in Gogs permits authenticated users to execute arbitrary commands on the server by embedding Git’s "--exec" flag in branch names when using the "Rebase before merging" option; Rapid7 confirmed the flaw and released a Metasploit module while no official patch yet exists, so administrators should disable open registration, restrict repository creation and merges, audit for suspicious branch names and log errors, and place instances behind access controls until fixed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.