Yet another RCE in Gogs, but it's fixed this time!
aikido.dev | vulnerability | #rce | #gitlab | #xss | #path-traversal | #cve | #aikido | #gogs | #cve-2026-52813 | #git-hosting
Summary
Aikido walks through three fixed Gogs flaws—an API-reachable path-traversal RCE (CVE-2026-52813), a logic bug writing to read-only repos, and a Jupyter-render XSS—plus one unpatched bypass.
Why it matters
This vulnerability coverage helps defenders validate exposure and prioritize remediation.
- Vendor
- Gogs
- Product
- Gogs
- Published
- Collected
Skip to content