
Critical Gogs Path Traversal Flaw Enables Remote Code Execution via Git Hooks
A critical path traversal vulnerability in Gogs, the self-hosted Git service, could let authenticated attackers achieve remote code execution by planting malicious Git hooks outside the intended repository storage directory. Tracked as CVE-2026-52813, the flaw arises from an API endpoint that accepted unsanitized organization usernames and passed them to a filesystem path-construction routine. Aikido researcher […]
The post Critical Gogs Path Traversal Flaw Enables Remote Code Execution via Git Hooks appeared first on Cyber Security News.