Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs
Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0.
02 / AFFECTED SOFTWARE
Affected packages
53 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: gogs.io/gogs before v0.14.0.
# IDOR: Cross-Repository Comment Deletion via DeleteComment ## Summary The `POST /:owner/:repo/issues/comments/:id/delete` endpoint does not verify that the comment belongs to the repository specified in the URL. This allows a repository administrator to delete comments from any other repository by supplying arbitrary comment IDs, bypassing authorization controls. ## Vulnerability Details | Field | Value | |-------|-------| | Affected File | `internal/route/repo/issue.go` | | Affected Function | `DeleteComment` (lines 955-968) | | Secondary File | `internal/database/comment.go` | | Secondary Function | `DeleteCommentByID` (lines 505-520) | ## Root Cause The vulnerability exists due to insufficient authorization validation in the comment deletion flow: ### 1. Missing Repository Ownership Check in DeleteComment In `internal/route/repo/issue.go`, the function retrieves a comment by ID without verifying repository ownership: ```go func DeleteComment(c *context.Context) { comment, err := database.GetCommentByID(c.ParamsInt64(":id")) if err != nil { c.NotFoundOrError(err, "get comment by ID") return } // Only checks if user is comment poster OR admin of the CURRENT repo (from URL) if c.UserID() != comment.PosterID && !c.Repo.IsAdmin() { c.NotFound() return } else if comment.Type != database.CommentTypeComment { c.Status(http.StatusNoContent) return } // No verification that comment.IssueID belongs to c.Repo.Repository.ID! if err = database.DeleteCommentByID(c.User, comment.ID); err != nil { c.Error(err, "delete comment by ID") return } c.Status(http.StatusOK) } ``` ### 2. Database Layer Performs No Authorization In `internal/database/comment.go`, the deletion function performs no repository validation: ```go func DeleteCommentByID(doer *User, id int64) error { comment, err := GetCommentByID(id) if err != nil { if IsErrCommentNotExist(err) { return nil } return err } // Directly deletes without checking repository ownership sess := x.NewSession() defer sess.Close() if err = sess.Begin(); err != nil { return err } if _, err = sess.ID(comment.ID).Delete(new(Comment)); err != nil { // ... } // ... } ``` ## Proof of Concept ### Prerequisites 1. Two users: **Alice** (attacker) and **Bob** (victim) 2. Alice is admin of `alice/attacker-repo` 3. Bob has created an issue with a comment on `bob/victim-repo` 4. Attacker needs to obtain the comment ID from victim's repository (e.g., ID: 42) ### HTTP Request ```http POST /alice/attacker-repo/issues/comments/42/delete HTTP/1.1 Host: gogs.example.com Cookie: i_like_gogs=<alice_session_token> ```
Gogs is an open source self-hosted Git service. In versions 0.13.4 and below, the DeleteComment API does not verify that the comment belongs to the repository specified in the URL. This allows a repository administrator to delete comments from any other repository by supplying arbitrary comment IDs, bypassing authorization controls. The DeleteComment function retrieves a comment by ID without verifying repository ownership and the Database function DeleteCommentByID performs no repository validation. This issue has been fixed in version 0.14.0.
05 / REFERENCES
Further evidence
- https://github.com/gogs/gogs/commit/1b226ca48dc8b3e95cc1c41229d72819c960a1b7
- https://github.com/gogs/gogs/security/advisories/GHSA-jj5m-h57j-5gv7
- https://nvd.nist.gov/vuln/detail/CVE-2026-25120
- https://github.com/gogs/gogs
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25120.json