Vulnerability record · CVE-2020-15867 · published 16 October 2020
CVE-2020-15867: Gogs git hook feature allows authenticated remote code execution
Gogs · Gogs
The git hook feature in Gogs 0.5.5 through 0.12.2 lets an authenticated user execute code on the server. The flaw also enables privilege escalation when hook access is granted to a non-administrative user, and the UI does not warn that the action is unsafe.
Description
The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution. There can be a privilege escalation if access to this hook feature is granted to a user who does not have administrative privileges. NOTE: because this is mentioned in the documentation but not in the UI, it could be considered a "Product UI does not Warn User of Unsafe Actions" issue.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.2 with high EPSS and public exploit references, but exploitation requires an authenticated account with hook privileges.
What it is
The git hook feature in Gogs 0.5.5 through 0.12.2 lets an authenticated user execute code on the server. The flaw also enables privilege escalation when hook access is granted to a non-administrative user, and the UI does not warn that the action is unsafe.
Impact
An attacker with a valid account gains remote code execution on the Gogs host, and a low-privileged user can escalate to administrative-level control of the server.
Attack surface
Reachable over the network through the git hook feature; the CVSS vector shows network access with high privileges required and no user interaction.
Exploitation
Not listed in CISA KEV, but EPSS is 0.87416 (99.7th percentile) and references are tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade Gogs past 0.12.2 to a fixed release as the first action.
- Restrict git hook configuration to administrative accounts only.
- Audit and remove hook access from non-administrative users.
- Monitor or disable custom git hooks where the feature is not required.
Detection
- Review Gogs audit logs for hook creation or modification events, especially by non-admin users.
- Inspect repository hook directories for unexpected or recently added scripts.
- Alert on server-side process execution spawned by the Gogs service account.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/162123/Gogs-Git-Hooks-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.fzi.de/en/news/news/detail-en/artikel/fsa-2020-3-schwachstelle-in-gitea-1125-und-gogs-0122-ermoeglicht-ausfu | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/162123/Gogs-Git-Hooks-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.fzi.de/en/news/news/detail-en/artikel/fsa-2020-3-schwachstelle-in-gitea-1125-und-gogs-0122-ermoeglicht-ausfu | ExploitThird Party Advisory |
Track CVE-2020-15867 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-15867), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.