Gogs Under Fire: Critical RCE Flaw Turns Git Repos Into Hacker Playgrounds
Security researchers have uncovered a critical vulnerability in Gogs, a widely used self-hosted Git platform, carrying a CVSS score of 9.4. The flaw allows authenticated users to achieve remote code execution (RCE) by exploiting a weakness in how the service handles git rebase operations. By injecting malicious arguments into these commands, an attacker can bypass traditional security barriers and run arbitrary code on the underlying server. With over 1,100 instances currently exposed online, administrators are urged to update their installations immediately to prevent potential system compromise.