Gogs Zero Day Grants Remote Code Execution
Gogs self-hosted Git service has an unpatched zero day that hands attackers remote code execution on exposed instances.
The flaw requires a basic user account, but default open registration can make exploitation easy. No CVE assigned yet. It affects internet-facing deployments running the latest versions.
Anyone running Gogs directly reachable from the internet needs to isolate or take it offline until a fix ships.
Public technical details are available.
