Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially crafted branch name that injects the --exec flag into the git rebase command during the "Rebase before merging" merge operation.
PoC
id: CVE-2026-52806
info:
name: Gogs <= 0.14.2 - Authenticated RCE via git rebase Argument Injection
author: DhiyaneshDk,pdteam
severity: critical
description: |
Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially crafted branch name that injects the --exec flag into the git rebase command during the "Rebase before merging" merge operation.
impact: |
Authenticated users can execute arbitrary code on the server, potentially leading to full system compromise.
remediation: This vulnerability is fixed in 0.14.3.
reference:
- https://www.cve.org/CVERecord?id=CVE-2026-52806
- https://github.com/portbuster1337/CVE-2026-52806
- https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/gogs_rebase_rce.rb
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
cvss-score: 9.9
cve-id: CVE-2026-52806
epss-score: 0.07934
epss-percentile: 0.94591
cwe-id: CWE-77
cpe: cpe:2.3:a:gogs:gogs:*:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 1
vendor: gogs
product: gogs
shodan-query: title:"Sign In - Gogs"
google-query: intitle:"Sign In - Gogs"
fofa-query: title="sign in - gogs"
tags: cve,cve2026,gogs,rce,argument-injection,git,authenticated,passive,vkev
http:
- method: GET
path:
- "{{BaseURL}}/user/login"
matchers-condition: and
matchers:
- type: word
part: body
words:
- '<meta property="og:description" content="Gogs is a painless self-hosted Git service.">'
- '<meta name="description" content="Gogs is a painless self-hosted Git service" />'
- "<title>Sign In - Gogs</title>"
condition: or
- type: status
status:
- 200
- type: dsl
dsl:
- compare_versions(gogs_version, '<= 0.14.2')
extractors:
- type: regex
name: gogs_version
part: body
group: 1
regex:
- 'Version: (\d+\.\d+\.\d+)'
internal: true
- type: regex
group: 1
regex:
- 'Version: (\d+\.\d+\.\d+)'
part: body
# digest: 490a0046304402201879829ab45b9fc7ed626714a6a984b4e86d47e3ac4b60396e62d0124138f8c002201b5c12264c6c25112c29cca2a2532ab14bf757403179c76c8f27779878a18bf1:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.