Critical RCE Bug in Gogs Git Service Remains Unpatched

TL;DR. A high-severity remote code execution vulnerability in the open-source Git service Gogs has no patch, with an exploit module now public. - The bug allows authenticated users to compromise servers, steal credentials, and modify code in repositories. - Rapid7 researcher Jonah Burgess reported the flaw in March, but Gogs maintainers have not responded. - A public Metasploit module is available, suggesting imminent exploitation in the wild.

Sources

Back to QLANKR News