{"id":"CVE-2026-52798","title":"Gogs has Stored XSS in `.ipynb` Preview","summary":"Gogs has Stored XSS in `.ipynb` Preview","severity":"high","cvss":8.9,"cwe":["CWE-79"],"vendor":"gogs","product":"gogs.io/gogs","ecosystem":"go","affected":["gogs.io/gogs <= 0.14.2"],"patched":["gogs.io/gogs 0.14.3"],"published":"2026-06-22","updated":"2026-06-22","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-jq8v-rmf6-65jw","references":[{"url":"https://github.com/gogs/gogs/security/advisories/GHSA-jq8v-rmf6-65jw"},{"url":"https://github.com/gogs/gogs/pull/8319"},{"url":"https://github.com/gogs/gogs/commit/17b168b11ca759a7550e1f4bbd68bbde14db7785"},{"url":"https://github.com/gogs/gogs/releases/tag/v0.14.3"},{"url":"https://github.com/advisories/GHSA-jq8v-rmf6-65jw"}],"tags":["ghsa","go"],"epss":0.00429,"epssPercentile":0.34459,"ingestedAt":"2026-06-29T13:24:35.482Z","slug":"CVE-2026-52798","body":"## Overview\n\n# Summary\n\nAlthough `.ipynb` previews are sanitized on the server side via `/-/api/sanitize_ipynb`, the inserted content is **re-rendered on the client side without sanitization** using `marked()` on elements with the `.nb-markdown-cell` class. During this process, links containing schemes such as `javascript:` can be regenerated.\n\nAs a result, when a victim views an attacker-crafted `.ipynb` file and clicks the link, **arbitrary JavaScript is executed in the Gogs origin**, leading to a click-based Stored XSS.\n\n# Details\n\nAfter the rendered output of a `.ipynb` file is sanitized via `/-/api/sanitize_ipynb` and inserted into the DOM, **only the Markdown cell portions are re-rendered using `marked()` and overwritten in the DOM**. During this process, links with the `javascript:` scheme can be regenerated.\n\n`templates/repo/view_file.tmpl:42–71`\n\n```html\n{{else if .IsIPythonNotebook}}\n  <script>\n    $.getJSON(\"{{.RawFileLink}}\", null, function(notebook_json) {\n      var notebook = nb.parse(notebook_json);\n      var rendered = notebook.render();\n      $.ajax({\n        type: \"POST\",\n        url: '{{AppSubURL}}/-/api/sanitize_ipynb',\n        data: rendered.outerHTML,\n        processData: false,\n        contentType: false,\n      }).done(function(data) {\n        $(\"#ipython-notebook\").append(data);\n        $(\"#ipython-notebook code\").each(function(i, block) {\n          $(block).addClass(\"py\").addClass(\"python\");\n          hljs.highlightBlock(block);\n        });\n\n        // Overwrite image method to append proper prefix to the source URL\n        var renderer = new marked.Renderer();\n        var context = '{{.RawFileLink}}';\n        context = context.substring(0, context.lastIndexOf(\"/\"));\n        renderer.image = function (href, title, text) {\n          return `<img src=\"${context}/${href}\"`\n        };\n        $(\"#ipython-notebook .nb-markdown-cell\").each(function(i, markdown) {\n          $(markdown).html(marked($(markdown).html(), {renderer: renderer}));\n        });\n      });\n    });\n  </script>\n```\n\nWhile **regular HTML pages (including `.ipynb` preview pages)** are served **without a Content Security Policy (CSP)**, CSP headers are applied **only to attachment delivery routes**.\n\n`internal/cmd/web.go:323`\n\n```go\nc.Header().Set(\"Content-Security-Policy\", \"default-src 'none'; style-src 'unsafe-inline'; sandbox\")\n```\n\n\n# Steps to Reproduce\n\n1. As the attacker, add and push/commit a `.ipynb` file containing a `javascript:` link in a Markdown cell to a repository.\n\n   * Example (PoC):\n\n     ```json\n     {\n       \"nbformat\": 4,\n       \"nbformat_minor\": 2,\n       \"metadata\": {},\n       \"cells\": [\n         {\n           \"cell_type\": \"markdown\",\n           \"metadata\": {},\n           \"source\": [\n             \"[poc](javascript:alert(document.domain))\"\n           ]\n         }\n       ]\n     }\n     ```\n\n2. The victim opens the file on Gogs (e.g., `/<user>/<repo>/src/<branch>/poc.ipynb`).\n<img width=\"2386\" height=\"1218\" alt=\"image\" src=\"https://github.com/user-attachments/assets/b0d93fd8-c5ca-4058-8af0-98dee590d3ad\" />\n\n3. When the victim clicks the `poc` link displayed in the preview, `alert(document.domain)` is executed in the same Gogs origin.\n<img width=\"2390\" height=\"1388\" alt=\"image\" src=\"https://github.com/user-attachments/assets/0eb6ebe8-632c-4a41-8a11-46471514b4c4\" />\n\n# Minimum Required Privileges\n\n* **Attacker**: Ability to place a `.ipynb` file as a **regular (non-admin) user**\n\n  * For example: a general user who can create a public repository and add files.\n  * Or: write access (collaborator, etc.) to an existing repository that the victim will view.\n* **Victim**: Permission to view the repository (a click is required).\n\n# Impact\n\n* Unauthorized actions performed with the victim’s account privileges (e.g., repository settings changes, Issue operations,誘導 to token creation).\n* Theft of information accessible to the victim (repository/Issue/Wiki contents, tokens exposed in page context).\n* If the victim is an administrator, the impact may escalate to instance-wide configuration changes and user management.\n\n## Affected packages\n\n- `gogs.io/gogs <= 0.14.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `gogs.io/gogs 0.14.3`","depth":"twilight","depthScore":49,"depthScoreParts":{"impact":49,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}