Vulnerability Description
Gogs is an open source self-hosted Git service. Prior to 0.14.0, as an authorized user, an intruder can dictate the value which is passed to the git diff command which, together with bypassing the filtering of the passed value, allows the user to bypass the target directory and write the result of the comparison to any arbitrary path. This vulnerability is fixed in 0.14.0.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/gogs/gogs/security/advisories/GHSA-pm6v-2h4w-4rp2
- https://github.com/gogs/gogs/security/advisories/GHSA-pm6v-2h4w-4rp2
FAQ
What is CVE-2026-52797?
CVE-2026-52797 is a vulnerability with a CVSS score of 8.5 (HIGH). Gogs is an open source self-hosted Git service. Prior to 0.14.0, as an authorized user, an intruder can dictate the value which is passed to the git diff command which, together with bypassing the fil...
How severe is CVE-2026-52797?
CVE-2026-52797 has been rated HIGH with a CVSS base score of 8.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-52797?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.