Known CVE
Gogs <= 0.14.2 - Authenticated RCE via git rebase Argument Injection
Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially crafted branch name that injects the --exec flag into the git rebase command during the "Rebase before merging" merge operation.
CVE-2026-52806
Critical2026CVSS 9.9CWE-77
cve2026 · gogs · rce · argument-injection · git · authenticated · passive · vkev
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website