CVE-2026-52801

HIGH

Gogs: Ability to import local repositories via Mirror Settings

Title source: cna
STIX 2.1

Description

Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs Mirror Settings functionality provide an alternative way from the well protected New Migration functionality for any authenticated users to import local repositories. This issue stems from a lack of validation of SaveAddress function. This vulnerability is fixed in 0.14.3.

References (4)

Core 4

Scores

CVSS v3 8.1
EPSS 0.0057
EPSS Percentile 42.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (1)
gogs/gogs < 0.14.3
Published Jun 24, 2026
Tracked Since Jun 25, 2026