We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Gogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the .git directory and achieve remote command execution due to an insufficient patch for CVE-2024-39931. Unprivileged user accounts can execute arbitrary commands on the Gogs instance with the privileges of the account specified by RUN_USER in the configuration. Allowing attackers to access and alter any users' code hosted on the same instance. This issue has been patched in version 0.13.3.
Reserved 2024-12-27 | Published 2025-06-24 | Updated 2025-06-24 | Assigner GitHub_MCWE-552: Files or Directories Accessible to External Parties
github.com/gogs/gogs/security/advisories/GHSA-wj44-9vcg-wjq7
github.com/...ommit/77a4a945ae9a87f77e392e9066b560edb71b5de9
github.com/gogs/gogs/releases/tag/v0.13.3
Support options