ELSEIF
Your brief EB
348 stories from 111 feeds 411 clusters Refreshed 7 minutes ago next pull 14:07

SECURITY Signal 430

Gogs patches path traversal RCE and two other bugs in 0.14.3, one bypass remains unpatched

Aikido Security reported an RCE via path traversal in Gogs organization names (CVE-2026-52813), a read-only repository write bug (CVE-2026-52810), and an XSS in a Jupyter rendering library (GHSA-6vxv-wg6j-5qwp), all fixed in version 0.14.3, though one bypass remains unpatched.

WHY IT MATTERS

Gogs has a history of RCEs that were slow to fix, but this cycle saw maintainers patch all reported issues in 0.14.3 after months of silence. Operators on older versions remain exposed to arbitrary filesystem writes through the API, and one reported bypass still requires a manual code patch.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

CVE-2026-52813 exploits unsanitized organization usernames in the API to traverse paths and write repository data to arbitrary filesystem locations.

02

Two additional vulnerabilities, a read-only repository write flaw (CVE-2026-52810) and an XSS in a Jupyter rendering library (GHSA-6vxv-wg6j-5qwp), were also fixed in 0.14.3.

03

One unpatched bypass of a reported vulnerability remains, with only a manual code patch provided by Aikido.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
Aikido Security's Blog Yet another RCE in Gogs, but it's fixed this time! Open ↗