Loading HuntDB...

GHSA-phm4-wf3h-pc3r

GitHub Security Advisory

Unpatched Remote Code Execution in Gogs

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.

Affected Packages

Go gogs.io/gogs
Affected versions: 0 (last affected: 0.13.0)

Related CVEs

Key Information

GHSA ID
GHSA-phm4-wf3h-pc3r
Published
November 15, 2024 6:30 PM
Last Modified
November 20, 2024 4:44 PM
CVSS Score
7.5 /10
Primary Ecosystem
Go
Primary Package
gogs.io/gogs
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 14, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.