/Vulnerability Library

Gogs <= 0.14.2 - Authenticated RCE via git rebase Argument Injection

CVE-2026-52806
Verified

Description

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially crafted branch name that injects the --exec flag into the git rebase command during the "Rebase before merging" merge operation.

Severity

Critical

CVSS Score

9.9

Exploit Probability

8%

Affected Product

gogs

Published Date

August 17, 2026

Template Author

dhiyaneshdk, pdteam

CVE-2026-52806.yaml
9.9Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVE ID:
cve-2026-52806
CWE ID:
cwe-77

References

https://www.cve.org/CVERecord?id=CVE-2026-52806https://github.com/portbuster1337/CVE-2026-52806https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/gogs_rebase_rce.rb

Remediation Steps

This vulnerability is fixed in 0.14.3.