FlawAtlas
Search the atlas
CVE-2026-23633 Moderate

Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs

Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4.

Exploit probability 0.5%
Published February 17, 2026
Required by Not available
Last source change February 19, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

63 explicit affected versions

Go gogs.io/gogs
Go gogs.io/gogs

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2026:21483-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2026-23633

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, there is an arbitrary file read/write via path traversal in Git hook editing. This issue has been patched in versions 0.13.4 and 0.14.0+dev.

View original source
Open Source Vulnerabilities GO-2026-4453

Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.13.4.

View original source
Open Source Vulnerabilities GHSA-mrph-w4hh-gx3g

## Vulnerability Description In the endpoint: ``` /username/reponame/settings/hooks/git/:name ``` the `:name` parameter: * Is URL-decoded by **macaron routing**, allowing decoded slashes (`/`) * Is then passed directly to: ```go git.Repository.Hook("custom_hooks", name) ``` which internally resolves the path as: ```go filepath.Join(repoPath, "custom_hooks", name) ``` Because no path sanitization is applied, supplying `../` sequences allows access to **arbitrary paths outside the repository**. ### As a Result: * **GET:** Arbitrary file contents are displayed in the hook edit page textarea (**Local File Inclusion**). * **POST:** Existing files can be overwritten with attacker-controlled content (**Arbitrary File Write**). --- ## Attack Prerequisites * The attacker is an authenticated user * The attacker has **Admin or higher privileges** on the target repository * The attacker has the **AllowGitHook** permission (or is a site administrator) * The target file is readable/writable by the **Gogs process OS permissions** --- ## Attack Scenario 1. An attacker (with AllowGitHook + repository Admin privileges) accesses the Git hook edit URL 2. A path containing `../` is supplied in `:name`, fully URL-encoded using `%2f` 3. The server resolves `custom_hooks/../../...` without validation 4. Arbitrary file contents are displayed and existing files can be overwritten --- ## Potential Impact * **Sensitive information disclosure:** `app.ini`, databases, logs, environment variables, etc. * **Configuration or data tampering:** Overwriting existing files * **Secondary impact:** Extraction of `SECRET_KEY` and database credentials may allow token forging or further compromise

View original source

05 / REFERENCES

Further evidence