Executive brief
Gogs is an open-source self-hosted Git service used by organizations to manage source code. A vulnerability in the file upload system allows an attacker with repository write access to bypass security restrictions and write files anywhere on the server's filesystem that the Gogs service can access. This could lead to a complete takeover of the server, unauthorized access to other repositories, or persistent remote access via SSH.
Technical details
A path traversal and symlink following vulnerability exists in Gogs' UploadRepoFiles handler. While other file operations in Gogs use a 'hasSymlinkInPath' check to validate every component of a path, UploadRepoFiles only checks if the final leaf is a symlink. An attacker with repository write access can commit a directory symlink, then perform a multipart upload with a filename containing a literal backslash. On Linux, this backslash is preserved by filepath.Base but later converted to a forward slash by pathx.Clean, allowing the upload to be routed through the previously committed symlink. Because iox.CopyFile uses os.Create without O_NOFOLLOW, the kernel follows the symlink, allowing the attacker to overwrite sensitive files like .ssh/authorized_keys or git hooks. This issue is fixed in version 0.14.3.
Affected products
- Gogs Gogs < 0.14.3
Timeline
- 2026-06-07: patched: Fix merged into main branch and released in v0.14.3
- 2026-06-19: advisory: GitHub Security Advisory GHSA-89mr-xqfv-758m published
- 2026-06-24: disclosed: CVE-2026-52811 published to NVD