{"id":1083,"date":"2026-05-28T18:15:52","date_gmt":"2026-05-28T18:15:52","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1083"},"modified":"2026-05-28T18:15:52","modified_gmt":"2026-05-28T18:15:52","slug":"critical-gogs-rce-vulnerability-lets-any-authenticated-user-execute-arbitrary-code","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1083","title":{"rendered":"Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">May 28, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Open Source<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhaqRd_3DDSSASg_YzvuUEqv3elhvFWSjk56bXPoqJeNIWVo-K0giuJ3TNEXV-aYpnuVfOv00_VM428vIFVaMiuZzfL0dQdQvz0_xMNFq4CtrppgTZu5dupV0asq1wZjPW3FoMgUnyGMR_RgBpWT2oTnJFuhaldo3Cd3eNP-MOlDNhP9Uu2KDRiDpYHdoeq\/s1700-e365\/exploit-meta.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>A critical security vulnerability has been disclosed in Gogs, a popular open-source self-hosted Git service, that allows an authenticated user to execute arbitrary code under certain conditions.<\/p>\n<p>The security flaw, per Rapid7, is rated 9.4 on the CVSS scoring system. It does not have a CVE identifier.<\/p>\n<p>\u00abThe vulnerability allows any authenticated user to achieve remote code execution (RCE) on the server by creating a pull request with a malicious branch name that injects the &#8211;exec flag into git rebase during the &#8216;Rebase before merging&#8217; merge operation,\u00bb security researcher Jonah Burgess <a href=\"https:\/\/www.rapid7.com\/blog\/post\/ve-authenticated-rce-via-argument-injection-gogs-unfixed\/\">said<\/a>.<\/p>\n<p><a href=\"https:\/\/www.atlassian.com\/git\/tutorials\/merging-vs-rebasing\">Rebasing<\/a> is a Git action that&#8217;s used to take a sequence of commits from one feature branch and replay them on top of another base branch to create a linear project history. While \u00abgit rebase\u00bb solves the same problem as \u00abgit merge\u00bb &#8212; i.e., integrating changes from one branch into another &#8212; the former rewrites the project history by creating new commits for each commit in the original branch.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlabz-vpn-risk-2026-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhnNON5UeWywT7OcPNw7V4L7QNWnCnm7Xl_99Y9ek8dL-gRwx-bWxQM1TKqt8deqqrdpUyKMuuijAWyyPQVB0s0qf8ntQ6ldFAJLru-QUWhddKTopc7SeNbBBnd-TsfFyRPP-AAyDuclLlL6XHK4_LXqDC_7eyaz9pzToYr7U543MhrJ7qcK-89sVWHTQUZ\/s728-e100\/zz-2-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The \u00abgit rebase\u00bb action also accepts as an argument a shell command via an <a href=\"https:\/\/git-scm.com\/docs\/git-rebase#Documentation\/git-rebase.txt---execltcmdgt\">&#8211;exec flag<\/a> that&#8217;s executed after each commit is replayed. A notable aspect of the vulnerability is that it does not require admin privileges or interaction with other users. To pull off the attack, all an unauthenticated threat actor has to do is create an account and repository on any default-configured instance.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>\u00abAny registered user who creates a repo is automatically its owner,\u00bb Burgess said. \u00abFrom there, enabling rebase merging is a single toggle in settings, and the entire exploit chain can be operated without interaction from any other user.\u00bb<\/p>\n<p>In an alternative scenario, a user with write access to a repository where rebase is already enabled can exploit the flaw directly to obtain code execution. On Gogs instances where repository creation is restricted, an attacker is required to have write access to any repository that has rebase merging enabled.<\/p>\n<p><iframe loading=\"lazy\" title=\"Rapid7 Labs: Gogs RCE | Windows\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/YJ-AlRgQ9VE?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/p>\n<p>As of writing, the vulnerability remains unpatched despite it being reported to the maintainer on March 17, 2026. Successful exploitation of the bug could grant an attacker the ability to breach the server, access every repository on the instance, dump credentials, move to other network-accessible systems, and tamper with any hosted repository&#8217;s code.<\/p>\n<p>What&#8217;s more, it can result in a cross-tenant data breach, allowing the attacker to read other users&#8217; private repositories hosted on the same shared server. According to Rapid7, the flaw impacts all supported platforms, such as Windows, Linux, and macOS.<\/p>\n<p>There are an estimated 1,141 internet-facing Gogs instances. However, the actual figure is expected to be higher, given that most deployments are placed behind VPNs or internal networks.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>In the absence of a patch, the following recommendations are outlined &#8211;<\/p>\n<ul>\n<li>Restrict user registration (DISABLE_REGISTRATION = true in app.ini) to prevent untrusted users from creating accounts<\/li>\n<li>Restrict repository creation (MAX_CREATION_LIMIT = 0 in app.ini) to prevent users from creating their own repositories<\/li>\n<li>Audit rebase merge settings<\/li>\n<\/ul>\n<p>Rapid7 has also made a <a href=\"https:\/\/github.com\/rapid7\/metasploit-framework\/pull\/21515\">Metasploit module<\/a> that automates the full exploit chain against both Linux and Windows targets. The module supports two modes: a default mode where a temporary repository is created under the attacker&#8217;s account, the exploit is run, and the repository is deleted. The second approach targets a repository that the attacker already has write and merge access to.<\/p>\n<p>\u00abWhen the attacker creates and deletes their own repository, the only trace is an HTTP 500 in the server logs,\u00bb the cybersecurity expert said. \u00abWhen exploiting an existing repository, additional artifacts remain.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802May 28, 2026Vulnerability \/ Open Source A critical security vulnerability has been disclosed in Gogs, a popular open-source self-hosted Git service, that allows an authenticated user to execute arbitrary&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1084,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1222,1831,10,58,1832,1830,332,316,1745,68],"class_list":["post-1083","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-arbitrary","tag-authenticated","tag-code","tag-critical","tag-execute","tag-gogs","tag-lets","tag-rce","tag-user","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1083","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1083"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1083\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1084"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1083"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1083"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1083"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}