Signal

Critical remote code execution vulnerability in Gogs remains unpatched, raising concerns for open-source self-hosted Git services

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-05-28 11:24 UTCUpdated 2026-05-29 00:31 UTC
rss
vulnerabilityexploitssecurity_toolingincident_response
Source links open
Source links and full evidence are open here. Pro adds archive history, compare-over-time, alerts, exports, and workflow. Business adds Feed API integrations and team usage.
No card needed for the free brief.
Evidence trail (top sources)
top sources (4 domains)domains are deduped. counts indicate coverage, not truth.
4 top sources shown
Authenticated RCE via Argument Injection in Gogs (NOT FIXED)
Rapid7 Blog · News · rapid7.com · 2026-05-28 12:00 UTC
Overview

A critical argument injection vulnerability in Gogs, a popular open-source self-hosted Git service, allows any authenticated user to execute arbitrary code on the server.

Entities
Rapid7GogsGiteaRyan EmmonsJonah BurgessIonut Arghire
Score total
1.52
Momentum 24h
4
Posts
4
Origins
4
Source types
1
Duplicate ratio
0%
Why now
  • The vulnerability was disclosed over two months ago but remains unpatched, increasing risk.
  • Gogs is commonly used internally, so exploitation could lead to significant source code compromise.
  • Similar vulnerabilities in related platforms like Gitea show a broader trend of risks in self-hosted Git services.
Why it matters
  • The vulnerability allows remote code execution with minimal privileges, risking internal network security.
  • Unpatched status highlights challenges in maintaining security for open-source projects with small teams.
  • Default open registration and repo creation settings increase the attack surface for Gogs users.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
  • A critical argument injection vulnerability in Gogs allows any authenticated user to execute arbitrary code on the server.
  • The Gogs vulnerability remains unpatched more than two months after disclosure, with no response from the maintainer.
  • Gogs default settings enable easy exploitation by unauthenticated attackers who can create accounts and repositories.
  • A vulnerability in Gitea exposed 30,000 deployments to attacks compromising private container images, source code, and credentials.
How sources frame it
  • CSO Online: neutral
All evidence
All evidence
Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code
thehackernews · thehackernews.com · 2026-05-28 17:24 UTC
Authenticated RCE via Argument Injection in Gogs (NOT FIXED)
Rapid7 Blog · rapid7.com · 2026-05-28 12:00 UTC
Gitea Vulnerability Exposed 30,000 Deployments to Attacks
SecurityWeek · securityweek.com · 2026-05-28 11:24 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 4Origin domains: 4Duplicates: -
Showing 4 / 4
Top publishers (this list)
  • CSO Online (1)
  • thehackernews (1)
  • Rapid7 Blog (1)
  • SecurityWeek (1)
Top origin domains (this list)
  • csoonline.com (1)
  • thehackernews.com (1)
  • rapid7.com (1)
  • securityweek.com (1)