Public PoC for Flowise CVE-2026-40933 enables one-click RCE via chatflow imports on self-hosted instances. Gogs unauthenticated RCE remains unpatched with Metasploit module available.…
An unpatched 9.4-severity flaw in the popular self-hosted Git service Gogs lets any authenticated user run arbitrary code by injecting --exec into git rebase via a malicious branch name in a pull request.…
Gogs is reported to have a critical unpatched authenticated RCE vulnerability (CVSS 9.4) that allows users to execute arbitrary code via malicious branch names during rebase operations.…