Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Security Patch Release

Gogs Rebase Injection Remote Code Execution and 0.14.3 Patch Response

Updated 08.06.2026 19:18
Case score 59
Members 2 First seen 28.05.2026 17:25 Latest activity 08.06.2026 19:18

Overview

A critical **Gogs** argument injection flaw in the **Rebase before merging** workflow exposed Internet-facing servers to authenticated remote code execution until **version 0.14.3** shipped on June 7, 2026. The flaw affects releases up to **0.14.2** and **0.15.0+dev**, and default open registration plus unrestricted repository creation can lower the barrier to reach the vulnerable path on exposed deployments. Successful abuse could expose private repositories and sensitive secrets while enabling unauthorized code changes or further movement from the server. Available evidence still does not confirm in-the-wild exploitation of this specific flaw, but operators now have a vendor fix and interim hardening steps if patching must wait.
Latest development Open development history 1 earlier development Gogs 0.14.3 patches a critical argument injection flaw The Gogs maintainers released version 0.14.3 on June 7, 2026 to patch a critical argument injection vulnerability affecting all releases up to and including 0.14.2 and 0.15.0+dev. The fix closed a path that could let authenticated non-admin attackers compromise Internet-facing instances, read private repositories, steal credentials, move laterally, and alter hosted source code.
  1. Earlier development

    Rapid7 details an unpatched Gogs argument injection zero-day

    Rapid7 publicly detailed an unpatched zero-day in the Gogs self-hosted Git service on May 28, 2026, explaining how a malicious branch name can inject the "—exe"c flag into git rebase during the "Rebase before merging" operation and allow remote code execution, server compromise, repository access, credential dumping, and code modification. The report says the flaw affects Gogs 0.14.2 and 0.15.0+dev, can be triggered by authenticated attackers without admin privileges, and is especially exposed on default-configured servers with open registration enabled; Shadowserver also tracks over 2,400 exposed Gogs servers, most in Asia and Europe.

Signals

Impact signals
CVEs/products
Geographic context
Remediation

Technical intelligence

Existing Case data

Member happenings

Vulnerability Gogs self-hosted Git service argument injection zero-day remote code execution flaw
Updated 28.05.2026 17:25 Lead Contribution 59
Data Type Passwords Patch No Patch

An **unpatched zero-day** in **Gogs** exposes **Internet-facing instances** to **remote code execution** and possible credential theft. The flaw is an **argument injection** bug in the **Rebase before merging** path, and it affects **Gogs 0.14.2** and **0.15.0+dev**. Because default configurations allow **open registration** and unlimited repository creation, a non-admin attacker can reach the exploit chain with basic account access.

Security Patch Release Gogs 0.14.3 security update for argument injection flaw
Updated 08.06.2026 19:18 Context
Urgency Immediate Patch Patch Available

The **Gogs maintainers** shipped **version 0.14.3** to fix a critical **argument injection** zero-day that could let attackers compromise **Internet-facing instances** and reach **private repositories**. The issue affected **all releases up to 0.14.2** and **0.15.0+dev**, and exploitation required only **authenticated non-admin access**. Successful abuse could expose repositories, steal credentials, move laterally, and alter hosted source code. Rapid7 urged operators to **upgrade immediately** and use temporary hardening if patching must wait.