Gogs Zero-Day Gives Remote Code Execution
Gogs self-hosted Git service has an unpatched zero-day that hands attackers remote code execution on exposed instances.
Attackers reach the flaw through the web interface on Internet-facing servers. Exploitation requires a basic user account, but default open registration can make that easy.
Self-hosted Gogs deployments that face the Internet are directly exposed. Internal instances behind firewalls face lower risk.
The issue remains unpatched with no CVE assigned yet.
