Menu

#Gogs

5 posts

Feed·
5 of 5 posts
One-Click RCE Hits Flowise While Gogs Zero-Day Stays Unpatched
🖼️
0

One-Click RCE Hits Flowise While Gogs Zero-Day Stays Unpatched

WebProNews·Tim Toole·3 months ago
#3H3vFdVj
#webpronews#flowise#gogs#self#hosted#code

Public PoC for Flowise CVE-2026-40933 enables one-click RCE via chatflow imports on self-hosted instances. Gogs unauthenticated RCE remains unpatched with Metasploit module available.…

15s
Read More
Gogs Git Service Faces Unpatched RCE That Turns Any User Into Server Owner
🖼️
0

Gogs Git Service Faces Unpatched RCE That Turns Any User Into Server Owner

WebProNews·Sara Donnelly·4 months ago
#AlxcCwz3

An unpatched 9.4-severity flaw in the popular self-hosted Git service Gogs lets any authenticated user run arbitrary code by injecting --exec into git rebase via a malicious branch name in a pull request.…

15s
Read More
Critical Unpatched RCE Vulnerability Discovered in Gogs Git Service
🖼️
0

Critical Unpatched RCE Vulnerability Discovered in Gogs Git Service

DEV Community: infosec·BeyondMachines·4 months ago
#vL2E0lgW
#dev#gogs#full#server#beyondmachines#photo

Gogs is reported to have a critical unpatched authenticated RCE vulnerability (CVSS 9.4) that allows users to execute arbitrary code via malicious branch names during rebase operations.…

15s
Read More