CVE-2026-26195

MEDIUM

Gogs < 0.14.2 - Stored Cross-Site Scripting via Unsafe Template Rendering

Title source: llm
STIX 2.1

Description

Gogs is an open source self-hosted Git service. Prior to version 0.14.2, stored xss is still possible through unsafe template rendering that mixes user input with safe plus permissive sanitizer handling of data urls. This issue has been patched in version 0.14.2.

Scores

CVSS v3 6.1
EPSS 0.0019
EPSS Percentile 8.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
gogs/gogs < 0.14.2
Published Mar 05, 2026
Tracked Since Mar 06, 2026