
We also reported a logic bug that lets you write to read-only repositories (CVE-2026-52810) and an XSS in the Jupyter rendering library Gogs was using. One bypass we reported is still unpatched, so we include a manual code patch in the blog post. Gogs isn't actively maintained right now, so we recommend a different self-hosted Git solution for the time being.
Post summary
The post reports a logic bug and XSS in Gogs, notes that the bypass remains unpatched, provides a manual code patch, and advises switching to another self‑hosted Git solution.


