Home / May 29, 2026 / Story
0
#2 The Hacker News general May 28, 2026 at 17:24 UTC

Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code

By [email protected] (The Hacker News)

AI Summary

A critical CVSS 9.4 RCE vulnerability in Gogs, the open-source self-hosted Git service, allows any authenticated user to execute arbitrary code — no CVE identifier has been issued. Rapid7 discovered and disclosed the flaw affecting the platform used across an estimated 30,000+ deployments. The lack of a patch makes this an urgent risk for developer infrastructure teams.

Relevance score: 81.0/100

# More from May 29