← back
CVE-2026-23633mediumCWE-22

Gogs has arbitrary file read/write via path traversal in Git hook editing

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.5epss 0.5%
exploitation probability
0.5%top 63% of all CVEs
observed exploitation
nono source reports it
In short

Gogs allows attackers to read or write arbitrary files on the server by exploiting path traversal in the Git hook editing feature. This can lead to unauthorized data access or system compromise.

Technical detail

A path traversal vulnerability (CWE-22) in Gogs Git hook editor allows authenticated or unauthenticated attackers to escape the intended directory context using directory traversal sequences, enabling arbitrary file read/write operations with the privileges of the Gogs process.

Summary generated and translated by AI from the official description.
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, there is an arbitrary file read/write via path traversal in Git hook editing. This issue has been patched in versions 0.13.4 and 0.14.0+dev.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Affected products
gogs · gogs