Vulnerability Report

CVE-2026-52813

RCE

Title: Path Traversal leading to RCE via Git Hooks

Arbitrary File Access

Proof Of Concept

PoC Available for CVE-2026-52813

CWE Category CWE-23
Published Date Jun 24, 2026
Modified Date Jun 26, 2026
Exploit Status Available
Score 10.0 CVSS v3.1
Exploit Probability (EPSS)
1.11%

Vulnerability Summary

CVE-2026-52813: Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences (../) are accepted by Gogs, and repositories under them are written to paths following these path traversals. This allows storing/retrieving data for repositories at arbitrary locations on the filesystem. By creating nested structure of Git repositories, one can overwrite the other's hooks configuration to result in Remote Code Execution (RCE). This vulnerability is fixed in 0.14.3.

CVSS v3.1
Source Entity [email protected]
Severity CRITICAL
10.0
Attack Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
CHANGED
RAW VECTOR CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2026-52813 Exploits & PoCs (Proof Of Concept)

GitHub https://github.com/thecodeb0ss/CVE-2026-52813
View Code
MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data updated via NVD.

Attack Vector Matrix

Access Vector NETWORK
Complexity LOW
Privileges N/A
Interaction NONE
CVSS Vector String CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Stack

No specific products linked.