Description
Gogs is an open source self-hosted Git service. Prior to 0.14.3, GET /attachments/:uuid returns the raw attachment file without verifying whether the requester has view permission for the associated Issue/Comment/Release or the repository. In a test environment with REQUIRE_SIGNIN_VIEW = false, we confirmed that an unauthenticated user can download attachments belonging to a private repository. This vulnerability is fixed in 0.14.3.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/gogs/gogs/security/advisories/GHSA-p9f5-h3rx-j5qw
X_Refsource_Misc x_refsource_misc
https://github.com/gogs/gogs/releases/tag/v0.14.3
Scores
CVSS v3
7.5
EPSS
0.0038
EPSS Percentile
30.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-639
CWE-862
Status
published
Products (2)
gogs/gogs
< 0.14.3
gogs.io/gogs
0 - 0.14.3Go
Published
Jun 24, 2026
Tracked Since
Jun 25, 2026