FlawAtlas
Search the atlas
CVE-2024-44625 High

Unpatched Remote Code Execution in Gogs in gogs.io/gogs

Unpatched Remote Code Execution in Gogs in gogs.io/gogs

Exploit probability 14.9%
Published November 19, 2024
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

55 explicit affected versions

Go gogs.io/gogs
Go gogs.io/gogs

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities GHSA-phm4-wf3h-pc3r

Gogs <0.13.2 is vulnerable to symbolic link path traversal that enables remote code execution via the editFilePost function of internal/route/repo/editor.go.

View original source
Open Source Vulnerabilities CVE-2024-44625

Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.

View original source

05 / REFERENCES

Further evidence