Executive brief
Gogs is an open-source self-hosted Git service used by developers to manage source code. A security flaw allows an attacker to trick an organization owner into clicking a malicious link, which silently adds the attacker to the organization's "Owners" team. This gives the attacker full administrative control over the organization's repositories and data.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in Gogs prior to version 0.14.3 due to organization team and member management routes accepting state-changing operations via GET requests. Because these endpoints lacked CSRF protection and relied on top-level navigation, an attacker could craft a malicious URL that, when visited by an authenticated organization owner, performs actions such as adding, removing, or promoting members. Specifically, an attacker can add themselves to the 'Owners' team, achieving full administrative privileges over the organization. The fix, implemented in version 0.14.3, migrates these actions to POST-only endpoints and updates the UI templates to use POST forms.
Affected products
- Gogs Gogs < 0.14.3
Timeline
- 2026-06-05: patched: Fix committed to main branch
- 2026-06-07: advisory: Release v0.14.3 published
- 2026-06-24: disclosed: CVE published to NVD