CVE-2021-32546Critical▾ MidnightOS Command Injection in gogs
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.3 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
2.0%
2.0% → 2.1%
The malicious user is able to update a crafted config file into repository's .git directory with to gain SSH access to the server. All installations with repository upload enabled (default) are affected.
Repository file updates are prohibited to its .git directory. Users should upgrade to 0.12.8 or the latest 0.13.0+dev.
N/A
N/A
If you have any questions or comments about this advisory, please post on #6555.
gogs.io/gogs < 0.12.8Upgrade to a patched release:
gogs.io/gogs 0.12.8Connected by shared product, vendor, weakness, or advisory.
CVE-2026-52797High· 8.5Gogs: Overwriting critical files results in a denial of service
CVE-2025-64719Medium· 4.9Gogs has a Denial of Service in repository/wiki file listing web pages
CVE-2026-25119HighGogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers
CVE-2026-47267MediumGogs has SSRF in webhook deliveries
CVE-2026-52796Low· 3.5Gogs has DoS in rendering issue index pattern
CVE-2026-52798High· 8.9Gogs has Stored XSS in `.ipynb` Preview