github.com
https://github.com/gogs/gogs CVE-2026-52797
HIGH
Gogs: Overwriting critical files results in a denial of service
Record summary
CVE-2026-52797 has a selected CVSS score of 8.5 (high).
Description
Gogs is an open source self-hosted Git service. Prior to 0.14.0, as an authorized user, an intruder can dictate the value which is passed to the git diff command which, together with bypassing the filtering of the passed value, allows the user to bypass the target directory and write the result of the comparison to any arbitrary path. This vulnerability is fixed in 0.14.0.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 25, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | < 0.14.0 | affected | |
gogs.io/gogsBrowse Go / gogs.io/gogs | GitHub Advisory | Before 0.14.0 · Fixed in 0.14.0 | affected |
References
3github.comConfirmation
https://github.com/gogs/gogs/security/advisories/GHSA-pm6v-2h4w-4rp2 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-52797