FOFA[verified]@fofabotPoC
Two critical RCE CVEs (CVE-2026-52813, CVE-2026-52806) in self‑hosted Gogs have a publicly available PoC, detailed exploitation steps, and a patch to version 0.14.3.
Netlas.io[verified]@Netlas_ioPoC
Three newly disclosed gogs RCE vulnerabilities have PoCs available, but no active exploitation or patch information is provided; the post includes technical details such as RCE type and a 10.0 CVSS rating.
YogSotho[verified]@YogSoth0Disclosure
The tweet discloses CVE‑2026‑52813 (CVSS 10.0) as a path‑traversal RCE in Gogs ≤0.14.2, outlining how attackers can write malicious Git hooks via organization‑name traversal, but provides no PoC, exploit code, patch information, or evidence of active exploitation.
Upwind Security MDR[verified]@UpwindMDRDisclosure
Gogs is exposed to remote code execution through git rebase option injection (CVE-2026-52806); detailed exploitation steps are outlined, and a patched release is advised.
pdnuclei-bot@pdnuclei_botDisclosure
CVE-2026-52806 is a critical authenticated RCE affecting Gogs <=0.14.2, with argument injection through git rebase. A PoC or template is available via the Project Discovery link; no patch, workaround, or active exploitation reported.
CCB Alert@CCBalertPatch
The post announces multiple critical Gogs vulnerabilities (CVE‑2026‑52813, 2026‑52806, 2026‑52811) that allow remote code execution and urges users to apply patches immediately, as detailed in the linked advisory.
DailyCVE@dailycveDisclosure
The post announces a newly disclosed CVE affecting Gogs, highlighting argument injection in PR merge that leads to remote code execution, but lacks any evidence of public PoC, exploit code, or patch status.