← Vulnerability feed

Vulnerability record · CVE-2022-0415 · published 21 March 2022

CVE-2022-0415: Gogs repository file upload allows remote command execution

Gogs · Gogs

Gogs before 0.12.6 fails to properly validate files uploaded to a repository, allowing an authenticated user to achieve remote command execution. The flaw combines improper input validation (CWE-20) with unrestricted file upload (CWE-434), and a public exploit reference exists, making it a practical risk for exposed Gogs instances.

8.8 CVSS 3.1 High EPSS 65% · top 0.8% CWE-20 · Improper input validationCWE-434 · Unrestricted file upload
8.8CVSS 3.1 base score, v2 6.5
65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityCVSS 8.8 with low privileges required, no user interaction, and a public exploit reference, though it is not in KEV and requires an authenticated account.

What it is

Gogs before 0.12.6 fails to properly validate files uploaded to a repository, allowing an authenticated user to achieve remote command execution. The flaw combines improper input validation (CWE-20) with unrestricted file upload (CWE-434), and a public exploit reference exists, making it a practical risk for exposed Gogs instances.

Impact

An attacker with a valid low-privileged account can execute arbitrary commands on the server hosting Gogs, leading to full compromise of confidentiality, integrity and availability of that host.

Attack surface

Reached over the network through the repository file upload functionality; the CVSS vector indicates low privileges are required and no user interaction is needed.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.65237, 99.2nd percentile) and the huntr.dev reference is tagged Exploit, indicating public exploit code is available.

What to do

  • Upgrade Gogs to 0.12.6 or later, which contains the patch commit 0fef3c9082269e9a4e817274942a5d7c50617284.
  • If immediate upgrade is not possible, restrict repository upload permissions to trusted users and disable or limit the upload feature.
  • Place Gogs behind authentication and network controls so only trusted users can reach the upload endpoint.
  • Monitor the Gogs host for unexpected child processes or outbound connections originating from the web service account.

Detection

  • Review Gogs upload and repository activity logs for unusual or unexpected file uploads, especially executable or script content.
  • Alert on process creation events where the Gogs service account spawns shells or system utilities.
  • Monitor for outbound network connections from the Gogs server to unfamiliar hosts.
  • Audit accounts with repository write or upload permissions for signs of compromise or misuse.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-0415 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2025-8110Gogs PutContents API symlink handling allows remote code executionThe PutContents API in Gogs mishandles symbolic links, letting a user write file content through a symlink and escape the intended repository path (C…KEVEPSS 85%analysed9.9CVE-2024-39930Gogs argument injection vulnerabilityThe built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated atta…EPSS 7.7%9.9CVE-2024-39931Gogs internal file deletion via path handling flawGogs through 0.13.0 allows deletion of internal files. The flaw is a path handling issue (CWE-552) that lets a user with a valid account remove files…EPSS 53%analysed9.9CVE-2024-39932Gogs code injection vulnerabilityGogs through 0.13.0 allows argument injection during the previewing of changes.EPSS 17%9.8CVE-2024-56731Gogs vulnerabilityGogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the .git directory and achieve rem…EPSS 1.2%9.8CVE-2022-1884Gogs os command injection vulnerabilityA remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to imp…EPSS 1.8%9.8CVE-2022-2024Gogs OS command injection before 0.12.11Gogs, a self-hosted Git service, contains an OS command injection flaw (CWE-78) in versions prior to 0.12.11. The CVSS 3.1 vector rates it 9.8 critic…EPSS 98%analysed9.8CVE-2022-1986Gogs os command injection vulnerabilityOS Command Injection in GitHub repository gogs/gogs prior to 0.12.9.EPSS 4.5%

Source: NIST National Vulnerability Database (record CVE-2022-0415), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.