gogs.io/gogs Security Analysis
gogs.io/gogs has 18 known security vulnerabilities in Go Modules. Upgrade to version 0.14.3 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.
Actively Exploited
CISA has confirmed this package has vulnerabilities under active exploitation. Prioritize updating immediately.
Recommended safe version: 0.14.3
Upgrading to 0.14.3 or later resolves all 18 known vulnerabilities in gogs.io/gogs. Run: go get gogs.io/gogs@v0.14.3
Is gogs.io/gogs in your project?
Check if you're affected and upgrade to 0.14.3 to stay secure.
Active Exploitation Warning
One or more vulnerabilities in this package are known to be actively exploited in the wild. Immediate action is recommended.
Vulnerabilities
18 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.
| CVE / GHSA | Severity | Affected | Fixed In |
|---|---|---|---|
| CVE-2025-8110 Gogs vulnerable to a bypass of CVE-2024-55947 | HIGH | All versions | No fix available |
| CVE-2026-52813 Gogs has Path Traversal in organization name that results in RCE through Git hooks | CRITICAL | All versions | 0.14.3 |
| CVE-2026-52806 Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge | CRITICAL | All versions | 0.14.3 |
| CVE-2025-64111 Gogs's update .git/config file allows remote command execution | CRITICAL | All versions | 0.13.4 |
| CVE-2024-56731 Gogs allows deletion of internal files which leads to remote command execution | CRITICAL | All versions | 0.13.3 |
| CVE-2026-52811 Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym | CRITICAL | All versions | 0.14.3 |
| CVE-2024-39930 Gogs has an argument Injection in the built-in SSH server | CRITICAL | All versions | 0.13.1 |
| CVE-2024-39932 Gogs allows argument injection during the previewing of changes | CRITICAL | All versions | 0.13.1 |
| CVE-2026-25921 Gogs: Cross-repository LFS object overwrite via missing content hash verification | CRITICAL | All versions | 0.14.2 |
| CVE-2022-1986 OS Command Injection in file editor in Gogs | CRITICAL | All versions | 0.12.9 |
| CVE-2024-54148 Remote Command Execution in file editing in gogs | HIGH | All versions | 0.13.1 |
| CVE-2026-52800 Gogs Vulnerable to CSRF Leading to Organization Owner Takeover | HIGH | All versions | 0.14.3 |
| CVE-2026-52805 Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft | HIGH | All versions | 0.14.3 |
| CVE-2026-26022 Gogs: Stored XSS via data URI in issue comments | HIGH | All versions | 0.14.2 |
| CVE-2026-52797 Gogs: Overwriting critical files results in a denial of service | HIGH | All versions | 0.14.0 |
| CVE-2025-64175 Gogs Vulnerable to 2FA Bypass via Recovery Code | HIGH | All versions | 0.13.4 |
| CVE-2024-55947 Path Traversal in file update API in gogs | HIGH | All versions | 0.13.1 |
| CVE-2026-52816 Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS | MEDIUM | All versions | 0.14.3 |
About This Data
Vulnerability data for gogs.io/gogs is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.
CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Related Go Modules Packages
Other packages in this ecosystem, ranked by shared vulnerabilities where available.
Check Your Dependencies
Scan your project to check if you're using a vulnerable version of gogs.io/gogs.