- Notifications
You must be signed in to change notification settings - Fork5.1k
Security: gogs/gogs
Security
SECURITY.md
Only the latest minor version releases are supported (>= 0.13) for accepting vulnerability reports and patching fixes.
Existing vulnerability reports are being tracked inGitHub Security Advisories.
Important
StartingNov 9, 2023 00:00 UTC, only security vulnerabilities reported throughGitHub Security Advisories are accepted.Pre-existing vulnerability reported throughhttps://huntr.dev/ or email (security@gogs.io) will continue to be worked through.
- Report an advisory for the vulnerability.
- Please be aware thatonly advisories reported in plain English will be reviewed.
- Project maintainers review the advisory:
- Ask clarifying questions
- Make sure there was no prior advisory exists for the same vulnerability
- Confirm or deny the vulnerability
- Once the advisory is accepted, the reporter may submit a patch or wait for project maintainers to patch.
- The latter is usually significantly slower.
- Patch releases will be made for the supported versions.
- After 14 days of the release, publish the corresponding advisory onGitHub Security Advisories.
Thank you for making open source community a better place!
- Deletion of internal files allows remote command executionGHSA-wj44-9vcg-wjq7 published
Jun 24, 2025 byunknwonCritical - Argument Injection when tagging new releasesGHSA-m27m-h5gj-wwmg published
Dec 23, 2024 byunknwonHigh - Argument Injection during changes previewGHSA-9pp6-wq8c-3w2c published
Dec 23, 2024 byunknwonCritical - Deletion of internal filesGHSA-ccqv-43vm-4f3w published
Dec 23, 2024 byunknwonCritical - Argument Injection in the built-in SSH serverGHSA-vm62-9jw3-c8w3 published
Dec 23, 2024 byunknwonCritical - Path Traversal in file update APIGHSA-qf5v-rp47-55gg published
Dec 23, 2024 byunknwonCritical - Path Traversal in file editing UIGHSA-r7j8-5h9c-f6fx published
Dec 23, 2024 byunknwonCritical - Stored XSS in PDF rendererGHSA-xh32-cx6c-cp4v published
Jun 24, 2025 byunknwonModerate - OS Command Injection in repo editor on case-insensitive file systemsGHSA-pfvh-p8qp-9ww9 published
Feb 25, 2023 byunknwonCritical - Stored XSS AssigneeGHSA-3ghq-jqx4-4c4f published
Feb 25, 2023 byunknwonCritical
Learn more about advisories related togogs/gogs in theGitHub Advisory Database