Gogs is a self-hosted Git service designed for smaller teams and organizations, presenting a narrowly scoped but strategically important attack surface as it often runs in trusted internal environments and manages source-code access. Vulnerabilities affecting the product skew strongly toward critical severity and frequently acquire public exploit code, reflecting the authentication, input handling, and system integration demands of a code-repository application. The exposure recurs persistently through path-traversal, cross-site scripting, missing authorization, OS command injection, and server-side request forgery weaknesses—a pattern characteristic of user-facing web services that interact with underlying version-control operations and file systems. Because Gogs deployments often control access to sensitive codebases and CI/CD systems, these vulnerability classes carry outsized impact relative to the product's narrow user base. Live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gogs over time
Signals from CVEs in this vendor scope (49 CVEs).
49 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-8110HIGH Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code. | Dec 10, 2025 | 8.8 | 97 | YES | YES |
CVE-2022-2024CRITICAL OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11. | Feb 25, 2023 | 9.8 | 83 | NO | NO |
CVE-2020-15867HIGH The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution. There can be a privilege escalation if access to this hook feature is granted to a | Oct 16, 2020 | 7.2 | 81 | NO | YES |
CVE-2022-0415HIGH Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6. | Mar 21, 2022 | 8.8 | 75 | NO | YES |
CVE-2024-55947HIGH Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the server to gain SSH access to the server. The vulnerability is f | Dec 23, 2024 | 8.8 | 68 | NO | NO |
CVE-2022-32174CRITICAL In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover. | Oct 11, 2022 | 9.0 | 60 | NO | NO |
CVE-2018-18925CRITICAL Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the file session provider in file.go. | Nov 4, 2018 | 9.8 | 60 | NO | YES |
CVE-2024-39931CRITICAL Gogs through 0.13.0 allows deletion of internal files. | Jul 4, 2024 | 9.9 | 59 | NO | NO |
CVE-2024-39930CRITICAL The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated attackers can exploit this by openi | Jul 4, 2024 | 9.9 | 47 | NO | YES |
CVE-2022-1993HIGH Path Traversal in GitHub repository gogs/gogs prior to 0.12.9. | Jun 9, 2022 | 8.1 | 46 | NO | NO |
Signals from CVEs in this vendor scope (49 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gogs.
Media articles that mention a CVE ID that affects a product developed by Gogs — matched by CVE ID, not by vendor name.