Insufficient checks and sanitization against argument injection and the fact thatgit rebaseaccepts the –exec flag, which tells Gogs to run a shell command after replaying each commit, allows attackers to include malicious arguments in branch names, which will be executed after each replayed commit.According to Rapid7, the vulnerability can be exploited without user interaction, as the attacker operates entirely within their own account and repository.“Since Gogs ships with open registration enabled by default and no limit on repository creation, an unauthenticated attacker can simply create an account and repository on any default-configured instance,” the cybersecurity firm says.Any repository owner can enable rebase merging with a single toggle in settings, and the entire exploit chain can be operated without interaction from any other user. Attackers with write access to repositories that have rebase enabled can exploit the flaw directly.“The result is arbitrary command execution as the Gogs server process user, giving the attacker the ability to compromise the server, read every repository on the instance (including other users’ private repos), dump credentials (password hashes, API tokens, SSH keys, 2FA secrets), pivot to other network-accessible systems, and modify any hosted repository’s code,” Rapid7 says.According to the cybersecurity firm, Gogs servers across Windows, Linux, and macOS that are running default configurations are affected. Instances with multiple user accounts, a default for many organizations, are impacted the most.Rapid7 has released a Metasploit module that automates the full exploit chain, as well as indicators of compromise (IoCs) to help defenders hunt for potential compromises.Gogs’ maintainers were notified of the security defect in mid-March. Although they acknowledged receiving the vulnerability report, no patch has been released as of the time of publishing.This is the second Gogs zero-day disclosed publicly over the past half a year. In December, Wiz detailed CVE-2025-8110, an improper symbolic link handling issue that had beenexploited as a zero-day for months.Related:Critical FortiClient EMS Vulnerability Exploited in Fresh AttacksRelated:Microsoft Patches Exploited UnDefend and RedSun Defender Zero-DaysRelated:New ‘Dirty Frag’ Linux Vulnerability Possibly Exploited in AttacksRelated:Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months
According to Rapid7, the vulnerability can be exploited without user interaction, as the attacker operates entirely within their own account and repository.“Since Gogs ships with open registration enabled by default and no limit on repository creation, an unauthenticated attacker can simply create an account and repository on any default-configured instance,” the cybersecurity firm says.Any repository owner can enable rebase merging with a single toggle in settings, and the entire exploit chain can be operated without interaction from any other user. Attackers with write access to repositories that have rebase enabled can exploit the flaw directly.“The result is arbitrary command execution as the Gogs server process user, giving the attacker the ability to compromise the server, read every repository on the instance (including other users’ private repos), dump credentials (password hashes, API tokens, SSH keys, 2FA secrets), pivot to other network-accessible systems, and modify any hosted repository’s code,” Rapid7 says.According to the cybersecurity firm, Gogs servers across Windows, Linux, and macOS that are running default configurations are affected. Instances with multiple user accounts, a default for many organizations, are impacted the most.Rapid7 has released a Metasploit module that automates the full exploit chain, as well as indicators of compromise (IoCs) to help defenders hunt for potential compromises.Gogs’ maintainers were notified of the security defect in mid-March. Although they acknowledged receiving the vulnerability report, no patch has been released as of the time of publishing.This is the second Gogs zero-day disclosed publicly over the past half a year. In December, Wiz detailed CVE-2025-8110, an improper symbolic link handling issue that had beenexploited as a zero-day for months.Related:Critical FortiClient EMS Vulnerability Exploited in Fresh AttacksRelated:Microsoft Patches Exploited UnDefend and RedSun Defender Zero-DaysRelated:New ‘Dirty Frag’ Linux Vulnerability Possibly Exploited in AttacksRelated:Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months
“Since Gogs ships with open registration enabled by default and no limit on repository creation, an unauthenticated attacker can simply create an account and repository on any default-configured instance,” the cybersecurity firm says.Any repository owner can enable rebase merging with a single toggle in settings, and the entire exploit chain can be operated without interaction from any other user. Attackers with write access to repositories that have rebase enabled can exploit the flaw directly.“The result is arbitrary command execution as the Gogs server process user, giving the attacker the ability to compromise the server, read every repository on the instance (including other users’ private repos), dump credentials (password hashes, API tokens, SSH keys, 2FA secrets), pivot to other network-accessible systems, and modify any hosted repository’s code,” Rapid7 says.According to the cybersecurity firm, Gogs servers across Windows, Linux, and macOS that are running default configurations are affected. Instances with multiple user accounts, a default for many organizations, are impacted the most.Rapid7 has released a Metasploit module that automates the full exploit chain, as well as indicators of compromise (IoCs) to help defenders hunt for potential compromises.Gogs’ maintainers were notified of the security defect in mid-March. Although they acknowledged receiving the vulnerability report, no patch has been released as of the time of publishing.This is the second Gogs zero-day disclosed publicly over the past half a year. In December, Wiz detailed CVE-2025-8110, an improper symbolic link handling issue that had beenexploited as a zero-day for months.Related:Critical FortiClient EMS Vulnerability Exploited in Fresh AttacksRelated:Microsoft Patches Exploited UnDefend and RedSun Defender Zero-DaysRelated:New ‘Dirty Frag’ Linux Vulnerability Possibly Exploited in AttacksRelated:Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months
Any repository owner can enable rebase merging with a single toggle in settings, and the entire exploit chain can be operated without interaction from any other user. Attackers with write access to repositories that have rebase enabled can exploit the flaw directly.“The result is arbitrary command execution as the Gogs server process user, giving the attacker the ability to compromise the server, read every repository on the instance (including other users’ private repos), dump credentials (password hashes, API tokens, SSH keys, 2FA secrets), pivot to other network-accessible systems, and modify any hosted repository’s code,” Rapid7 says.According to the cybersecurity firm, Gogs servers across Windows, Linux, and macOS that are running default configurations are affected. Instances with multiple user accounts, a default for many organizations, are impacted the most.Rapid7 has released a Metasploit module that automates the full exploit chain, as well as indicators of compromise (IoCs) to help defenders hunt for potential compromises.Gogs’ maintainers were notified of the security defect in mid-March. Although they acknowledged receiving the vulnerability report, no patch has been released as of the time of publishing.This is the second Gogs zero-day disclosed publicly over the past half a year. In December, Wiz detailed CVE-2025-8110, an improper symbolic link handling issue that had beenexploited as a zero-day for months.Related:Critical FortiClient EMS Vulnerability Exploited in Fresh AttacksRelated:Microsoft Patches Exploited UnDefend and RedSun Defender Zero-DaysRelated:New ‘Dirty Frag’ Linux Vulnerability Possibly Exploited in AttacksRelated:Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months
“The result is arbitrary command execution as the Gogs server process user, giving the attacker the ability to compromise the server, read every repository on the instance (including other users’ private repos), dump credentials (password hashes, API tokens, SSH keys, 2FA secrets), pivot to other network-accessible systems, and modify any hosted repository’s code,” Rapid7 says.According to the cybersecurity firm, Gogs servers across Windows, Linux, and macOS that are running default configurations are affected. Instances with multiple user accounts, a default for many organizations, are impacted the most.Rapid7 has released a Metasploit module that automates the full exploit chain, as well as indicators of compromise (IoCs) to help defenders hunt for potential compromises.Gogs’ maintainers were notified of the security defect in mid-March. Although they acknowledged receiving the vulnerability report, no patch has been released as of the time of publishing.This is the second Gogs zero-day disclosed publicly over the past half a year. In December, Wiz detailed CVE-2025-8110, an improper symbolic link handling issue that had beenexploited as a zero-day for months.Related:Critical FortiClient EMS Vulnerability Exploited in Fresh AttacksRelated:Microsoft Patches Exploited UnDefend and RedSun Defender Zero-DaysRelated:New ‘Dirty Frag’ Linux Vulnerability Possibly Exploited in AttacksRelated:Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months
According to the cybersecurity firm, Gogs servers across Windows, Linux, and macOS that are running default configurations are affected. Instances with multiple user accounts, a default for many organizations, are impacted the most.Rapid7 has released a Metasploit module that automates the full exploit chain, as well as indicators of compromise (IoCs) to help defenders hunt for potential compromises.Gogs’ maintainers were notified of the security defect in mid-March. Although they acknowledged receiving the vulnerability report, no patch has been released as of the time of publishing.This is the second Gogs zero-day disclosed publicly over the past half a year. In December, Wiz detailed CVE-2025-8110, an improper symbolic link handling issue that had beenexploited as a zero-day for months.Related:Critical FortiClient EMS Vulnerability Exploited in Fresh AttacksRelated:Microsoft Patches Exploited UnDefend and RedSun Defender Zero-DaysRelated:New ‘Dirty Frag’ Linux Vulnerability Possibly Exploited in AttacksRelated:Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months
Rapid7 has released a Metasploit module that automates the full exploit chain, as well as indicators of compromise (IoCs) to help defenders hunt for potential compromises.Gogs’ maintainers were notified of the security defect in mid-March. Although they acknowledged receiving the vulnerability report, no patch has been released as of the time of publishing.This is the second Gogs zero-day disclosed publicly over the past half a year. In December, Wiz detailed CVE-2025-8110, an improper symbolic link handling issue that had beenexploited as a zero-day for months.Related:Critical FortiClient EMS Vulnerability Exploited in Fresh AttacksRelated:Microsoft Patches Exploited UnDefend and RedSun Defender Zero-DaysRelated:New ‘Dirty Frag’ Linux Vulnerability Possibly Exploited in AttacksRelated:Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months
Gogs’ maintainers were notified of the security defect in mid-March. Although they acknowledged receiving the vulnerability report, no patch has been released as of the time of publishing.This is the second Gogs zero-day disclosed publicly over the past half a year. In December, Wiz detailed CVE-2025-8110, an improper symbolic link handling issue that had beenexploited as a zero-day for months.Related:Critical FortiClient EMS Vulnerability Exploited in Fresh AttacksRelated:Microsoft Patches Exploited UnDefend and RedSun Defender Zero-DaysRelated:New ‘Dirty Frag’ Linux Vulnerability Possibly Exploited in AttacksRelated:Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months
This is the second Gogs zero-day disclosed publicly over the past half a year. In December, Wiz detailed CVE-2025-8110, an improper symbolic link handling issue that had beenexploited as a zero-day for months.Related:Critical FortiClient EMS Vulnerability Exploited in Fresh AttacksRelated:Microsoft Patches Exploited UnDefend and RedSun Defender Zero-DaysRelated:New ‘Dirty Frag’ Linux Vulnerability Possibly Exploited in AttacksRelated:Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months
Related:Critical FortiClient EMS Vulnerability Exploited in Fresh AttacksRelated:Microsoft Patches Exploited UnDefend and RedSun Defender Zero-DaysRelated:New ‘Dirty Frag’ Linux Vulnerability Possibly Exploited in AttacksRelated:Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months
Source: SecurityWeek