Jorian[verified]@J0R1ANDisclosure
The post highlights the discovery of an unauthenticated RCE in Gogs 0.14.2 and points readers to a blog detailing the exploit, with a hint that a fix exists.
FOFA[verified]@fofabotPoC
The post discloses two high‑score RCE vulnerabilities in self‑hosted Gogs, shares a public PoC, lists foaa scan results, and notes the available patch to 0.14.3.
Netlas.io[verified]@Netlas_ioDisclosure
Three newly disclosed RCE vulnerabilities in gogs (CVE‑2026‑52813, CVE‑2026‑52806, CVE‑2026‑52811) with a 10.0 rating have been announced, with PoC available, but no active exploitation, patches, or debunking information is provided.
YogSotho[verified]@YogSoth0Disclosure
The tweet discloses a new Gogs vulnerability (CVE-2026-52813) that allows path traversal and chained RCE via malicious Git hooks, providing CVSS and technical details but no PoC or patch information.
Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
State-sponsored actors used the critical Gogs RCE CVE‑2026‑52813 (and n8n flaws) to exfiltrate 31 TB of data from 144 U.S. universities, employing signed driver abuse and AnyDesk for lateral movement—clear evidence of in‑the‑wild exploitation.
Kaitan ID Security[verified]@KaitanSecurityDisclosure
The text announces a critical path‑traversal vulnerability (CVE‑2026‑52813) in older Gogs releases, providing technical details but no PoC, exploit, or patch information.
Aikido Community Japan[verified]@AikidoCommJPPatch
Several severe RCE vulnerabilities in Gogs, including CVE-2026-52813, have been fixed in v0.14.3; the article urges organizations to apply the patch promptly.
Upwind Security MDR[verified]@UpwindMDRDisclosure
A newly disclosed CVE-2026-52813 reveals a critical path‑traversal flaw in Gogs enabling remote code execution through manipulated Git hooks; the vendor has yet to release a patch, so an update to a fixed version is recommended.