CVE-2024-56731
Gogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the .git directory and achieve remote command execution due to an insufficient patch for CVE-2024-39931. Unprivileged user accounts can execute arbitrary commands on the Gogs instance with the privileges of the account specified by RUN_USER in the configuration. Allowing attackers to access and alter any users' code hosted on the same instance. This issue has been patched in version 0.13.3.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.99%
- CWE
- CWE-552
- Published
- 2025-06-24
- Last modified
- 2026-03-13
Affected products
- gogs gogs
Weakness type
Related vulnerabilities
- CVE-2026-68831 — Windows Defender Firewall Service Information Disclosure Vulnerability
- CVE-2026-67402 — An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs...
- CVE-2026-85175 — SiYuan before v3.8.2 TLS Private Key Disclosure via getFile
- CVE-2026-82020 — Hermes Agent 0.16.0 < 0.17.0 Credential Store Overwrite via File-Write Tool
- CVE-2026-53580 — Trilium arbitrary file read and denial of service via file:// URLs in the automatic image-download feature
- CVE-2026-78051 — alexta69 MeTube Cookie File cookies.txt file access
- CVE-2026-54457 — TensorZero: Arbitrary file read and SSRF in TensorZero Gateway's internal object storage endpoint
- CVE-2026-63042 — Apache InLong: Missing authorization on DataNode management endpoints