GO · JUNE 2026 · EARLY WARNING

Gogs RCE Vulnerability via Pull Request Branch Name Injection

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-QF6P-P7WW-CWR9Severity: CRITICAL

Gogs versions prior to 0.15.0 are reportedly vulnerable to Remote Code Execution (RCE) through a specially crafted pull request branch name. Users of affected versions should assess their exposure and consider upgrading.

What happened

An early warning has been issued regarding a critical vulnerability in Gogs, tracked as GHSA-QF6P-P7WW-CWR9. This vulnerability, reportedly affecting versions of Gogs prior to 0.15.0, allows authenticated users to achieve Remote Code Execution (RCE) on the server. The attack vector involves creating a pull request with a specially crafted branch name that injects the `--exec` flag into the `git rebase` command during the 'Rebase before merging' merge operation.

The vulnerability is under investigation, and the recommended action is to upgrade to Gogs 0.15.0 or later, which includes the fix for this issue. Users of affected versions should assess their exposure and consider upgrading as a precautionary measure. For more detailed information, consult the primary sources linked in the threat data.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If gogs is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats