Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-55947

68
FAUCET Score

CVE-2024-55947 is a critical arbitrary file write vulnerability affecting Gogs, an open-source self-hosted Git service. A malicious authenticated user can exploit this flaw to write files to arbitrary server paths, leading to SSH access and full system compromise. With a CVSS score of 8.8 (HIGH) and an EPSS score indicating high exploitability, this vulnerability poses a significant risk due to its low attack complexity and severe impact on confidentiality, integrity, and availability. This zero-day vulnerability is actively exploited in the wild, with multiple media outlets reporting its use to compromise hundreds of servers, despite the absence of public exploit code or a patch at the time of initial exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.13.1CPE matchmatch criteria
cpe:2.3:a:gogs:gogs:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.7HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
75.20%
Probability of exploitation in next 30 days
EPSS Percentile
99.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.7520 is in the 99th percentile among its peer group of 17,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: gogs.io/gogsFixed in: 0.13.1

Vendor Advisories (1)

goGHSA-qf5v-rp47-55gghigh

Path Traversal in file update API in gogs

Dec 23, 2024

References

github.com / gogs/gogs/commit/9a9388ace25bd646f5098cb9193d983332c34e41
Patch
github.com / gogs/gogs/issues/7582
Issue Tracking
github.com / gogs/gogs/pull/7859
Patch
github.com / gogs/gogs/security/advisories/GHSA-qf5v-rp47-55gg
ExploitVendor Advisory