Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

New Gogs zero-day flaw lets hackers get remote code execution

0
Critical
Vulnerabilityremoterce
Published: Thu May 28 2026 (05/28/2026, 14:25:43 UTC)
Source: Bleeping Computer

Description

An unpatched zero-day vulnerability in the Gogs self-hosted Git service can allow attackers to gain remote code execution (RCE) on Internet-facing instances. [...]

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/28/2026, 14:33:43 UTC

Technical Analysis

This vulnerability is an argument injection flaw in the Merge() code path of Gogs, a self-hosted Git service written in Go. It allows authenticated users without admin privileges to inject the "--exec" flag into the git rebase command during the 'Rebase before merging' operation, resulting in remote code execution as the Gogs server process user. Due to default settings that enable open registration and unlimited repository creation, attackers can easily create accounts and repositories to exploit this flaw. Successful exploitation permits attackers to compromise the server, access all repositories including private ones, extract credentials such as password hashes, API tokens, SSH keys, and 2FA secrets, and pivot to other network systems. The vulnerability was reported on March 17, 2026, but no patch or detailed response has been provided by the Gogs maintainers as of the publication date. This flaw is similar in nature to previously patched argument injection vulnerabilities but affects a previously unpatched code path.

Potential Impact

The impact of this vulnerability is critical. Attackers can achieve remote code execution on Gogs servers, leading to full compromise of the affected system. This includes unauthorized access to all repositories hosted on the server, including private repositories, theft of sensitive credentials, and potential lateral movement to other networked systems. The flaw affects all Gogs servers with default configurations, which are common, thereby increasing the attack surface significantly. No active exploitation has been reported yet, but the exposure of thousands of Gogs servers online, especially in Asia and Europe, presents a substantial risk.

Mitigation Recommendations

As of the latest information, no official patch or fix is available from the Gogs maintainers. The vulnerability remains unpatched despite being reported months ago. Organizations using Gogs should consider disabling open registration and limiting repository creation as temporary mitigations to reduce the attack surface. Monitoring for unusual repository creation and merge operations may help detect exploitation attempts. Users should follow updates from the Gogs maintainers closely and apply any official patches immediately once released. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/security/new-gogs-zero-day-flaw-lets-hackers-get-remote-code-execution/","fetched":true,"fetchedAt":"2026-05-28T14:33:33.149Z","wordCount":850}

Threat ID: 6a18523de29bf47b50f66536

Added to database: 5/28/2026, 2:33:33 PM

Last enriched: 5/28/2026, 2:33:43 PM

Last updated: 5/29/2026, 5:30:21 PM

Views: 19

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses