CVE-2024-44625

HIGH8.8EPSS 81.8%

Remote Code Execution in Gogs

Published: 11/15/2024Modified: 10/8/2025
Also known as:GHSA-phm4-wf3h-pc3rGO-2024-3275

Description

Gogs <0.13.2 is vulnerable to symbolic link path traversal that enables remote code execution via the editFilePost function of internal/route/repo/editor.go.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References (6)