CVE-2024-44625
High
Unpatched Remote Code Execution in Gogs in gogs.io/gogs
Unpatched Remote Code Execution in Gogs in gogs.io/gogs
Exploit probability
14.9%
Published
November 19, 2024
Required by
Not available
Last source change
March 3, 2026
02 / AFFECTED SOFTWARE
Affected packages
55 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
GO-2024-3275
View original source
Unpatched Remote Code Execution in Gogs in gogs.io/gogs
Open Source Vulnerabilities
GHSA-phm4-wf3h-pc3r
View original source
Gogs <0.13.2 is vulnerable to symbolic link path traversal that enables remote code execution via the editFilePost function of internal/route/repo/editor.go.
Open Source Vulnerabilities
CVE-2024-44625
View original source
Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.
05 / REFERENCES
Further evidence
- https://fysac.github.io/posts/2024/11/unpatched-remote-code-execution-in-gogs
- https://github.com/advisories/GHSA-phm4-wf3h-pc3r
- https://nvd.nist.gov/vuln/detail/CVE-2024-44625
- https://github.com/gogs/gogs
- https://gogs.io
- https://pkg.go.dev/vuln/GO-2024-3275
- https://fysac.github.io/posts/2024/11/unpatched-remote-code-execution-in-gogs/
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/44xxx/CVE-2024-44625.json
- https://gogs.io/