Rapid7 and BleepingComputer reported an unpatched zero-day in the self-hosted Git service Gogs that allows authenticated remote code execution through argument injection in the pull request rebase workflow. The flaw affects current releases including 0.14.2 and 0.15.0+dev, and likely earlier versions that support rebase merging. An attacker can abuse the "Rebase before merging" feature by supplying a malicious branch name that is passed into a git rebase command without a proper option separator, enabling use of Git's --exec flag to run attacker-controlled shell commands as the Gogs server process user.
The issue is rated CVSSv4 9.4 and is considered especially dangerous on default-configured instances because open registration and unrestricted repository creation are enabled by default, lowering the barrier to exploitation. Successful attacks could expose private repositories, stored credentials, and secrets, enable code tampering and supply-chain compromise, and support lateral movement deeper into victim networks. Rapid7 said no vendor patch was available at publication time and released a Metasploit module for Linux and Windows, while separate reporting noted Gogs maintainers had only acknowledged the report. The disclosures follow broader scrutiny of Git hosting platforms, including a recently disclosed Gitea flaw, CVE-2026-27771, that can expose private container images without authentication on versions prior to 1.26.2.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Gogs released version 0.14.3 on June 7, 2026 to patch the critical argument injection remote code execution flaw previously disclosed by Rapid7. The patch addressed the vulnerability affecting releases up to and including 0.14.2 and 0.15.0+dev.
With no official vendor patch available, Rapid7 submitted a pull request containing a proposed fix for the authenticated Gogs RCE vulnerability. The company also recommended mitigations including disabling registration, restricting repository creation, and turning off 'Rebase before merging.'
Rapid7 publicly disclosed a critical authenticated remote code execution vulnerability in Gogs caused by argument injection in the 'Rebase before merging' feature. The company said the flaw affects Gogs 0.14.2 and 0.15.0+dev, released a Metasploit module for Linux and Windows exploitation, and noted no vendor patch was available at publication time.
BleepingComputer reports that Rapid7 researcher Jonah Burges reported the Gogs argument injection vulnerability to the maintainers in March. The maintainers had only acknowledged the report and had not issued a patch or further response by the time of publication.
Researchers disclosed CVE-2026-27771 in Gitea, an unauthenticated flaw that allows pulling private container images from affected deployments. The disclosure said all versions prior to 1.26.2 are affected and advised upgrading to 1.26.2 or enabling REQUIRE_SIGNIN_VIEW as a workaround.
Rapid7 reported the authenticated Gogs remote code execution vulnerability to the maintainer on March 17, 2026. The flaw involved argument injection via the 'Rebase before merging' feature and remained unpatched at the time of later public disclosure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcebleepingcomputer.com
Open sourcescworld.com
Open sourcethecybersecguru.com
Open sourcecybersecuritynews.com
Open sourcerapid7.com
Open sourcebleepingcomputer.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.