A critical unpatched argument injection vulnerability in Gogs, the self-hosted Git service written in Go, allows any authenticated user to remotely execute code on a Gogs server via a malicious branch name during a merge operation. Rapid7 disclosed the flaw publicly after the Gogs maintainer failed to respond over two months. The exploit requires no admin privileges and can be triggered by any registered user on default-configured instances. Potential impact includes server compromise, cross-tenant data breaches, credential theft, lateral movement, and supply chain attacks. Until a patch is released, organizations should restrict network access to Gogs and disable open user registration. The incident highlights the security risks of relying on small, volunteer-maintained open source projects.

5m read timeFrom infoworld.com
Post cover image
235 Impressions