Gogs has released version 0.14.3 to patch a critical zero-day argument injection vulnerability enabling remote code execution on all default-configured instances. Discovered by Rapid7 researcher Jonah Burgess, the flaw affects all Gogs releases up to 0.14.2 and 0.15.0+dev. Because Gogs ships with open registration and unlimited repository creation enabled by default, an unauthenticated attacker can register an account, create a repo, enable rebase merging, and execute the full exploit chain without any other user interaction. Exploitation allows reading any repository (including private ones), credential theft, lateral movement, and source code tampering. Over 2,300 internet-exposed Gogs servers are currently tracked by Shadowserver. Users who cannot patch immediately should disable open registration and restrict repository creation. This follows a similar RCE vulnerability (CVE-2025-8110) that was actively exploited in late 2025 and added to CISA's known exploited vulnerabilities catalog.

4m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Related Articles:
725 Impressions