All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

Critical Gogs RCE bug (CVSS 9.4) remains unpatched; exploit module now public

By

Jessica Lyons

1h ago· 3 min readenNews

Summary

A critical remote code execution (RCE) vulnerability rated 9.4/10 has been discovered in Gogs, a popular open-source self-hosted Git service. The flaw can be exploited by any authenticated user on a default installation to fully compromise servers, steal credentials and MFA secrets, or modify code in hosted repositories for supply-chain attacks. The security researcher reported the bug to project maintainers in March but has received no response, and no fix has been released yet. An exploit module is already publicly available.

Key quotes

· 3 pulled
A critical, remote code execution (RCE) bug in Gogs, a popular open-source self-hosted Git service, can be exploited by any authenticated user - no special privileges required
The flaw can fully compromise vulnerable servers, steal credentials and multi-factor authentication secrets, or even modify code in hosted repositories in a wide-reaching supply-chain attack
A security researcher reported the 9.4-rated flaw to project maintainers in March. Maintainers haven't responded to his messages since
Snippet from the RSS feed
Researcher reported the vuln in March. Maintainers haven't responded to his messages since

You might also wanna read

Security audit of Forgejo reveals numerous critical vulnerabilities

Security researcher Julien Voisin (jvoisin) conducted a security audit of Forgejo, the Git hosting platform that Fedora recently migrated to

dustri.org·1mo ago

How a botnet abused my open source project's cloud version to phish 14,000 people

The author, who runs an open source project management tool called Kaneo, discovered that a botnet had abused the hosted cloud version of th

andrej.sh·2d ago

VS Code Remote-SSH Vulnerability Enables Lateral Movement from Developer Machines to Cloud Servers

A critical vulnerability in Visual Studio Code's Remote-SSH extension creates a post-compromise attack path enabling threat actors to pivot

cybersecuritynews.com·2d ago

AI security audit of FreeBSD kernel reveals 15 bugs including RCEs and a hypervisor escape

An AI audit of FreeBSD uncovered 15 kernel bugs, including 3 remote code execution vulnerabilities, 5 local privilege escalation flaws, and

blog.calif.io·2d ago

Microsoft bans security researcher from GitHub after zero-day exploit posts; researcher threatens retaliation

A security researcher known as Nightmare-Eclipse (Chaotic Eclipse) has been banned from Microsoft's GitHub platform after allegedly posting

tomshardware.com·3d ago

Microsoft bans security researcher from GitHub after zero-day exploit posts; researcher threatens retaliation

A security researcher known as Nightmare-Eclipse (Chaotic Eclipse) has been banned from Microsoft's GitHub platform after allegedly posting

tomshardware.com·3d ago