SECURITY Signal 430
Gogs patches path traversal RCE and two other bugs in 0.14.3, one bypass remains unpatched
Aikido Security reported an RCE via path traversal in Gogs organization names (CVE-2026-52813), a read-only repository write bug (CVE-2026-52810), and an XSS in a Jupyter rendering library (GHSA-6vxv-wg6j-5qwp), all fixed in version 0.14.3, though one bypass remains unpatched.
Gogs has a history of RCEs that were slow to fix, but this cycle saw maintainers patch all reported issues in 0.14.3 after months of silence. Operators on older versions remain exposed to arbitrary filesystem writes through the API, and one reported bypass still requires a manual code patch.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
CVE-2026-52813 exploits unsanitized organization usernames in the API to traverse paths and write repository data to arbitrary filesystem locations.
Two additional vulnerabilities, a read-only repository write flaw (CVE-2026-52810) and an XSS in a Jupyter rendering library (GHSA-6vxv-wg6j-5qwp), were also fixed in 0.14.3.
One unpatched bypass of a reported vulnerability remains, with only a manual code patch provided by Aikido.
THE CLUSTER
↗