CVE-2026-52806Disclosure

MEDIUMCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially crafted branch name that injects the --exec flag into the git rebase command during the "Rebase before merging" merge operation. This vulnerability is fixed in 0.14.3.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 7 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-06-26); latest day: 1
  • 7 total mentions across 6 days

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-06-23: 1Mentions · 2026-06-24: 1Mentions · 2026-06-25: 1Mentions · 2026-06-26: 2Mentions · 2026-06-27: 1Mentions · 2026-08-18: 1PoC Mentioned / Linked · 2026-06-26: 1PoC Mentioned / Linked · 2026-06-27: 1PoC Mentioned / Linked · 2026-08-18: 1Exploit Tool / Code · 2026-06-26: 1Patch / Workaround · 2026-06-24: 1Patch / Workaround · 2026-06-25: 1Patch / Workaround · 2026-06-26: 1Technical Details · 2026-06-23: 1Technical Details · 2026-06-24: 1Technical Details · 2026-06-25: 1Technical Details · 2026-06-26: 2Technical Details · 2026-06-27: 1Technical Details · 2026-08-18: 106-2306-2406-2506-2606-2708-18
Signal classification3 categories
Disclosure
457.1%
PoC
228.6%
Patch
114.3%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-06-231
Disclosure1
2026-06-241
Disclosure1
2026-06-251
Patch1
2026-06-262
Disclosure1PoC1
2026-06-271
PoC1
2026-08-181
Disclosure1
Full discourse7 posts
  • FOFA@fofabot
    PoC

    ⚠️⚠️ CVE-2026-52813 (CVSS 10.0) + CVE-2026-52806 (CVSS 9.9): Self-hosted Gogs ≤0.14.2 hit by chained RCE flaws (org-name path traversal → Git hooks; PR merge git rebase injection); public PoC released — patch to 0.14.3. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJHb2dzIg== 🎯42.1K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="Gogs" PoC: https://gist.github.com/JorianWoltjer/4b72063338b27140f4439c524d98f2b9 🔖Refer: https://securityonline.info/gogs-rce-vulnerability/ #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    Two critical RCE CVEs (CVE-2026-52813, CVE-2026-52806) in self‑hosted Gogs have a publicly available PoC, detailed exploitation steps, and a patch to version 0.14.3.

    417164176.4K
    14.6K followersView on X
  • Netlas.io@Netlas_io
    PoC

    CVE-2026-52813 & CVE-2026-52806 & CVE-2026-52811: Three RCE vulnerabilities in gogs, up to 10.0 rating 🔥 Recently disclosed vulnerabilities in gogs allow an attacker to execute arbitrary code. PoC exist for all three! 👉 https://nt.ls/A9o6h

    Post summary

    Three newly disclosed gogs RCE vulnerabilities have PoCs available, but no active exploitation or patch information is provided; the post includes technical details such as RCE type and a 10.0 CVSS rating.

    0402341.8K
    7.7K followersView on X
  • YogSotho@YogSoth0
    Disclosure

    #CVE-2026-52813 + CVE-2026-52806 #Exploit#Gogs ≤0.14.2 Chained #RCE: Org-Name Path Traversal → #Git Hooks → PR Merge Rebase Injection CVE-2026-52813 (CVSS 10.0): Path traversal via organization name allows writing arbitrary files to the server filesystem, specifically malicious Git hooks into target repository .git/hooks/ directories. #security #hacking #0days

    Post summary

    The tweet discloses CVE‑2026‑52813 (CVSS 10.0) as a path‑traversal RCE in Gogs ≤0.14.2, outlining how attackers can write malicious Git hooks via organization‑name traversal, but provides no PoC, exploit code, patch information, or evidence of active exploitation.

    01033476
    1.8K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-52806 - critical 🚨 Gogs <= 0.14.2 - Authenticated RCE via git rebase Argument Injection > Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenti... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-52806 @pdnuclei #NucleiTemplat...

    Post summary

    CVE-2026-52806 is a critical authenticated RCE affecting Gogs <=0.14.2, with argument injection through git rebase. A PoC or template is available via the Project Discovery link; no patch, workaround, or active exploitation reported.

    00001252
    1.2K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Multiple Critical Vulnerabilities in #Gogs. CVE-2026-52813, CVE-2026-52806 &amp; CVE-2026-52811, max CVSS: 10.0. These flaws can lead to remote code execution #RCE! #Patch #Patch #Patch More info: https://ccb.belgium.be/advisories/warning-multiple-vulnerabilities-gogs-allow-remote-code-execution-patch-immediately

    Post summary

    The post announces multiple critical Gogs vulnerabilities (CVE‑2026‑52813, 2026‑52806, 2026‑52811) that allow remote code execution and urges users to apply patches immediately, as detailed in the linked advisory.

    00000375
    7.2K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Gogs git rebase option injection leads to RCE (CVE-2026-52806) Gogs is vulnerable to remote code execution in the server-side “Rebase before merging” workflow, where it invokes git rebase using a pull request’s base branch name. The root cause is improper argument handling/command option injection: the branch name is passed to git rebase without a “--” separator, allowing it to be parsed as flags (e.g., injecting --exec). An attacker exploits this by authenticating to the Gogs instance and submitting a crafted pull request with a maliciously named base branch, then triggering (or waiting for) a rebase-before-merge operation. Successful exploitation results in arbitrary command execution as the Gogs process user, enabling full server compromise, cross-tenant repo access, and credential exposure on shared instances. 👉 Affected: http://gogs.io/gogs (versions with “Rebase before merging” invoking git rebase without “--”) | Upgrade to a patched release that adds “--” separator / blocks option-like branch names (No fix yet - treat as suspicious)

    Post summary

    Gogs is exposed to remote code execution through git rebase option injection (CVE-2026-52806); detailed exploitation steps are outlined, and a patched release is advised.

    0000077
    226 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔵 Gogs: Argument Injection in PR Merge Leading to Remote Code Execution (#CVE-2026-52806) -DC-Jun2026-579 https://dailycve.com/gogs-argument-injection-in-pr-merge-leading-to-remote-code-execution-cve-2026-52806-dc-jun2026-579/

    Post summary

    The post announces a newly disclosed CVE affecting Gogs, highlighting argument injection in PR merge that leads to remote code execution, but lacks any evidence of public PoC, exploit code, or patch status.

    0000047
    216 followersView on X

Explore more