CVE Explorer
CVE-2026-52797
Gogs is an open source self-hosted Git service. Prior to 0.14.0, as an authorized user, an intruder can dictate the value which is passed to the git diff command which, together with bypassing the filtering of the passed value, allows the user to bypass the target directory and write the result of the comparison to any arbitrary path. This vulnerability is fixed in 0.14.0.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"gogs","vendor":"gogs","versions":[{"status":"affected","version":"< 0.14.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:871c3e042f97ee5d735ae31013ed9d989998eda1874a5501f40d1bfc5ec6705b · sha256:9f8d62a50990b90f… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:871c3e042f97ee5d735ae31013ed9d989998eda1874a5501f40d1bfc5ec6705b · sha256:9f8d62a50990b90f… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:871c3e042f97ee5d735ae31013ed9d989998eda1874a5501f40d1bfc5ec6705b · sha256:9f8d62a50990b90f… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["exploit"],"url":"https://github.com/gogs/gogs/security/advisories/GHSA-pm6v-2h4w-4rp2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:871c3e042f97ee5d735ae31013ed9d989998eda1874a5501f40d1bfc5ec6705b · sha256:9f8d62a50990b90f… · /containers/adp/0/references/0
{"name":"https://github.com/gogs/gogs/security/advisories/GHSA-pm6v-2h4w-4rp2","tags":["x_refsource_CONFIRM"],"url":"https://github.com/gogs/gogs/security/advisories/GHSA-pm6v-2h4w-4rp2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:871c3e042f97ee5d735ae31013ed9d989998eda1874a5501f40d1bfc5ec6705b · sha256:9f8d62a50990b90f… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.