Skip to main content
EPSS 0.2%top 90%

CVE-2026-53552: CWE-639: Authorization Bypass Through User-Controlled Key in zhenorzz goploy

0
Critical
Published: 08/31/2026 (08/31/2026, 18:46:41 UTC)
Source: GCVE Database
Vendor/Project: zhenorzz
Product: goploy

Description

Goploy is an open-source automation deployment system. In versions 1.17.5 and prior, Project.AddFile, Project.EditFile, Project.RemoveFile, and Project.Edit in cmd/server/api/project/handler.go accept a project or project-file row id from the JSON body and act on it without checking that the project belongs to the caller's namespace. The corresponding model.ProjectFile.GetData and model.Project.GetData queries filter only by row id. A user holding the manager role (or any role that includes the FileSync / EditProject permission) in their own namespace can read, write, or delete files in any project across the install, and can rewrite any project's git remote URL by submitting the foreign id in the body. The git-URL primitive escalates to RCE on the next deploy because Edit runs git remote set-url on the project's working tree. At time of publication, there are no known publicly available patches.

CVSS v3.1

Score 9.6critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Affected software

Goghsa
github.com/zhenorzz/goploy
Affected versions
<=1.17.5

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/07/2026, 11:07:10 UTC

Technical Analysis

In goploy versions 1.17.5 and prior, several API handlers (Project.AddFile, Project.EditFile, Project.RemoveFile, and Project.Edit) accept project or project-file row IDs from JSON input and perform actions without verifying that the project belongs to the caller's namespace. The underlying data queries filter only by row ID, not ownership. Consequently, a user with manager role or roles including FileSync/EditProject permissions can manipulate files or project settings across the entire installation. Specifically, the ability to rewrite the git remote URL escalates to remote code execution because the Edit handler runs 'git remote set-url' on the project's working tree during deployment. At the time of publication, no official patches or fixes are available.

Potential Impact

An attacker with manager-level permissions in their own namespace can bypass authorization controls to access and modify files in any project on the goploy installation. This includes reading, writing, and deleting files arbitrarily. Furthermore, the attacker can change the git remote URL of any project, which leads to remote code execution during the next deployment process. This vulnerability compromises confidentiality, integrity, and can lead to full system compromise. There are no known public exploits in the wild yet.

Mitigation Recommendations

At the time of this report, no official patches or fixes are available for this vulnerability. Users should monitor the vendor's advisories for updates. Until a fix is released, restrict manager and FileSync/EditProject permissions to trusted users only and consider limiting access to the deployment system to reduce risk.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-26rh-24rg-j3vv
Osv Schema Version
1.4.0
Aliases
["CVE-2026-53552"]
Ecosystems
["Go"]
Database Specific Severity
CRITICAL
Cvss Version
3.1

Threat ID: 6a4e4ee7c9d9e3dbe3289b43

Added to database: 07/08/2026, 13:21:43 UTC

Last enriched: 09/07/2026, 11:07:10 UTC

Last updated: 09/13/2026, 23:59:00 UTC

Views: 85

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses