Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
weaponized-exploit-availabilityinternet-facing-service-vulnerabilityproof-of-concept-releaserapid-weaponization

Unpatched Gogs Argument Injection Flaw Enables Authenticated RCE

Updated 14d agoFirst seen May 28, 202611 sources

Rapid7 and BleepingComputer reported an unpatched zero-day in the self-hosted Git service Gogs that allows authenticated remote code execution through argument injection in the pull request rebase workflow. The flaw affects current releases including 0.14.2 and 0.15.0+dev, and likely earlier versions that support rebase merging. An attacker can abuse the "Rebase before merging" feature by supplying a malicious branch name that is passed into a git rebase command without a proper option separator, enabling use of Git's --exec flag to run attacker-controlled shell commands as the Gogs server process user.

The issue is rated CVSSv4 9.4 and is considered especially dangerous on default-configured instances because open registration and unrestricted repository creation are enabled by default, lowering the barrier to exploitation. Successful attacks could expose private repositories, stored credentials, and secrets, enable code tampering and supply-chain compromise, and support lateral movement deeper into victim networks. Rapid7 said no vendor patch was available at publication time and released a Metasploit module for Linux and Windows, while separate reporting noted Gogs maintainers had only acknowledged the report. The disclosures follow broader scrutiny of Git hosting platforms, including a recently disclosed Gitea flaw, CVE-2026-27771, that can expose private container images without authentication on versions prior to 1.26.2.

Share:
Unpatched Gogs Argument Injection Flaw Enables Authenticated RCE
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Jun 7, 202616d ago

Gogs patched critical authenticated RCE in version 0.14.3

Gogs released version 0.14.3 on June 7, 2026 to patch the critical argument injection remote code execution flaw previously disclosed by Rapid7. The patch addressed the vulnerability affecting releases up to and including 0.14.2 and 0.15.0+dev.

Gogs patches critical zero-day enabling remote code execution
May 29, 202625d ago

Rapid7 submitted proposed fix for unpatched Gogs RCE

With no official vendor patch available, Rapid7 submitted a pull request containing a proposed fix for the authenticated Gogs RCE vulnerability. The company also recommended mitigations including disabling registration, restricting repository creation, and turning off 'Rebase before merging.'

No fix yet for critical Gogs RCE bug - exploit module is out
May 28, 202626d ago

Rapid7 disclosed unpatched Gogs RCE and released Metasploit module

Rapid7 publicly disclosed a critical authenticated remote code execution vulnerability in Gogs caused by argument injection in the 'Rebase before merging' feature. The company said the flaw affects Gogs 0.14.2 and 0.15.0+dev, released a Metasploit module for Linux and Windows exploitation, and noted no vendor patch was available at publication time.

Authenticated RCE via Argument Injection in Gogs (NOT FIXED)

Rapid7 reported Gogs authenticated RCE flaw to maintainers

BleepingComputer reports that Rapid7 researcher Jonah Burges reported the Gogs argument injection vulnerability to the maintainers in March. The maintainers had only acknowledged the report and had not issued a patch or further response by the time of publication.

New Gogs zero-day flaw lets hackers get remote code execution
May 27, 202627d ago

Gitea private image exposure flaw disclosed with patch guidance

Researchers disclosed CVE-2026-27771 in Gitea, an unauthenticated flaw that allows pulling private container images from affected deployments. The disclosure said all versions prior to 1.26.2 are affected and advised upgrading to 1.26.2 or enabling REQUIRE_SIGNIN_VIEW as a workaround.

Gitea Vulnerability Exposes Private Container Images without Authentication
Mar 17, 20263mo ago

Rapid7 reported Gogs RCE flaw to maintainer

Rapid7 reported the authenticated Gogs remote code execution vulnerability to the maintainer on March 17, 2026. The flaw involved argument injection via the 'Rebase before merging' feature and remained unpatched at the time of later public disclosure.

Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

31 LINKEDOpen in app
Affected products
13 linked
GogsGitGitlabMetasploitWindowsGiteaMacosLinuxMsys2PowershellForgejoUbuntuDocker
Organizations
12 linked
Rapid7GogsShodanWizGitLabShadowServer FoundationGitHubThe RegisterDigitaloceanGiteaForgejoNoscope
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.