Description
Gogs is an open source self-hosted Git service. Prior to 0.14.3, three API endpoints — PATCH /api/v1/repos/:owner/:repo/issue-tracker, PATCH /api/v1/repos/:owner/:repo/wiki, and POST /api/v1/repos/:owner/:repo/mirror-sync — are gated by reqRepoWriter() rather than reqRepoAdmin(). The equivalent operations in the web UI sit behind reqRepoAdmin, which requires AccessMode >= AccessModeAdmin. A write-level collaborator (who has AccessMode == AccessModeWrite < AccessModeAdmin) can therefore call these API endpoints directly to disable the native issue tracker or wiki, inject attacker-controlled external tracker/wiki URLs that redirect all repository visitors, or trigger mirror sync — none of which they are authorized to do. This vulnerability is fixed in 0.14.3.
Severity (CVSS)
| Base score | 7.1 |
|---|---|
| Severity | High |
| Version | CVSS 3.1 |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L |
| Provided by | CNA |
Weaknesses
- CWE-863 — CWE-863: Incorrect Authorization
- CWE-269 — CWE-269: Improper Privilege Management
Affected products
| Vendor | Product | Versions |
|---|---|---|
| gogs | gogs | < 0.14.3 |
References
- https://github.com/gogs/gogs/security/advisories/GHSA-268j-37xf-pp52 (x_refsource_CONFIRM)
- https://github.com/gogs/gogs/pull/8327 (x_refsource_MISC)
- https://github.com/gogs/gogs/commit/6283462119bd8894f1599d70339b5e823f99954a (x_refsource_MISC)
- https://github.com/gogs/gogs/releases/tag/v0.14.3 (x_refsource_MISC)
Generated from the official CVE List on 25 Jun 2026 10:14 UTC.