logo

Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code

ID: 80ba0610-318e-5277-8f07-73c658411503

STIX ID: report--80ba0610-318e-5277-8f07-73c658411503

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-05-28

Date Updated: 2026-05-29

Author: [email protected] (The Hacker News)

...
...

A critical RCE vulnerability in Gogs allows any registered user (or any user with write access to a repo where rebase merging is enabled) to execute arbitrary code by crafting a pull request with a malicious branch name that injects the --exec flag into git rebase during 'Rebase before merging'. Rapid7 rates the flaw 9.4 CVSS, it remains unpatched as of reporting, affects Windows/Linux/macOS, and a Metasploit module exists to automate exploitation; recommended mitigations include disabling registration, restricting repository creation, and auditing rebase merge settings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.