CVE-2026-52806
Gravedad CVSS v3.1:
CRÍTICA
Tipo:
CWE-77
Neutralización incorrecta de elementos especiales usados en un comando (Inyección de comando)
Fecha de publicación:
24/06/2026
Última modificación:
26/06/2026
Descripción
*** Pendiente de traducción *** Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially crafted branch name that injects the --exec flag into the git rebase command during the "Rebase before merging" merge operation. This vulnerability is fixed in 0.14.3.
Impacto
Puntuación base 3.x
9.90
Gravedad 3.x
CRÍTICA
Referencias a soluciones, herramientas e información
- https://github.com/gogs/gogs/commit/a9dbafbfd8e1020bacc626420238c01d75d03364
- https://github.com/gogs/gogs/pull/8301
- https://github.com/gogs/gogs/releases/tag/v0.14.3
- https://github.com/gogs/gogs/security/advisories/GHSA-qf6p-p7ww-cwr9
- https://github.com/gogs/gogs/security/advisories/GHSA-qf6p-p7ww-cwr9



