CVE-2026-52806 is an authenticated remote code execution vulnerability in Gogs affecting versions prior to 0.14.3. The flaw arises during pull request merging when the "Rebase before merging" operation invokes a git rebase command using attacker-controlled branch name input without sufficient neutralization of special command elements. By creating a pull request with a specially crafted branch name, an authenticated user can inject the --exec option into the git rebase invocation, causing arbitrary commands to be executed on the server in the context of the Gogs process. The issue is a command/argument injection condition in the merge workflow rather than a client-side issue, and exploitation occurs server-side when the vulnerable merge path is triggered.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a single Python exploit script (gogs.py) and a README. The script is a standalone authenticated RCE proof-of-concept for Gogs, targeting an argument injection flaw in the pull request merge flow where a branch name is passed to git rebase without a '--' separator. The exploit workflow is: preflight fingerprinting of a Gogs instance and version, registration-state detection, authentication via credentials/cookie/auto-registration, API token creation, temporary repository creation, enabling rebase-before-merge, local git repository setup, creation of a malicious branch named like --exec=<payload>, opening a pull request into that branch, and triggering merge via rebase to execute attacker-controlled shell commands on the server. It supports arbitrary command execution and reverse shells, and includes cleanup of temporary repositories/files afterward. The code also contains version fingerprint mappings, CSRF extraction logic, HTTP session handling, and local git subprocess orchestration. This is a real exploit rather than a detector, and while not part of a major framework, it is operational because it automates end-to-end exploitation with a basic customizable payload.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.