Skip to content

Known CVE

Gogs <= 0.14.2 - Authenticated RCE via git rebase Argument Injection

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially crafted branch name that injects the --exec flag into the git rebase command during the "Rebase before merging" merge operation.

CVE-2026-52806

Critical2026CVSS 9.9CWE-77

cve2026 · gogs · rce · argument-injection · git · authenticated · passive · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website