← Vulnerability feed

Vulnerability record · CVE-2022-2024 · published 25 February 2023

CVE-2022-2024: Gogs OS command injection before 0.12.11

Gogs · Gogs

Gogs, a self-hosted Git service, contains an OS command injection flaw (CWE-78) in versions prior to 0.12.11. The CVSS 3.1 vector rates it 9.8 critical with network reachability, no privileges and no user interaction, so a remote attacker can run operating system commands on the host. The record does not name the specific vulnerable endpoint or parameter.

9.8 CVSS 3.1 Critical EPSS 98% · top 0.1% CWE-78 · OS command injection
9.8CVSS 3.1 base score
98%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, combined with a 99.9th percentile EPSS score and a public exploit reference, makes this an urgent patch.

What it is

Gogs, a self-hosted Git service, contains an OS command injection flaw (CWE-78) in versions prior to 0.12.11. The CVSS 3.1 vector rates it 9.8 critical with network reachability, no privileges and no user interaction, so a remote attacker can run operating system commands on the host. The record does not name the specific vulnerable endpoint or parameter.

Impact

An attacker can execute arbitrary operating system commands with the privileges of the Gogs process, leading to full compromise of the server and any data or credentials it holds. Because the vector shows high confidentiality, integrity and availability impact, expect complete loss of control over the instance.

Attack surface

Reachable over the network per the AV:N vector, with no authentication (PR:N) and no user interaction (UI:N) required. The description does not identify the exact request path or input field, so the precise entry point is unknown from this record.

Exploitation

Not listed in CISA KEV, but EPSS is 0.97839 (99.9th percentile), indicating very high predicted exploitation activity. A public exploit reference is tagged on the huntr.dev bounty, and a patch commit is available.

What to do

  • Upgrade Gogs to 0.12.11 or later, applying the patch commit 15d0d6a94be0098a8227b6b95bdf2daed105ec41.
  • If immediate upgrade is not possible, restrict network access to the Gogs instance to trusted users and networks only.
  • Run the Gogs service under a low-privilege dedicated account with no unnecessary filesystem or shell access.
  • Monitor the Gogs host for unexpected child processes or shell invocations spawned by the Gogs service.

Detection

  • Alert on process creation events where the Gogs service account spawns shells (sh, bash, cmd, powershell) or unexpected binaries.
  • Inspect Gogs HTTP access logs for requests containing shell metacharacters (;, |, $(), backticks) in parameters.
  • Baseline normal Gogs child processes and flag deviations, especially outbound connections from the Gogs host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-2024 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2025-8110Gogs PutContents API symlink handling allows remote code executionThe PutContents API in Gogs mishandles symbolic links, letting a user write file content through a symlink and escape the intended repository path (C…KEVEPSS 85%analysed9.9CVE-2024-39930Gogs argument injection vulnerabilityThe built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated atta…EPSS 7.7%9.9CVE-2024-39931Gogs internal file deletion via path handling flawGogs through 0.13.0 allows deletion of internal files. The flaw is a path handling issue (CWE-552) that lets a user with a valid account remove files…EPSS 53%analysed9.9CVE-2024-39932Gogs code injection vulnerabilityGogs through 0.13.0 allows argument injection during the previewing of changes.EPSS 17%9.8CVE-2024-56731Gogs vulnerabilityGogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the .git directory and achieve rem…EPSS 1.2%9.8CVE-2022-1884Gogs os command injection vulnerabilityA remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to imp…EPSS 1.8%9.8CVE-2022-1986Gogs os command injection vulnerabilityOS Command Injection in GitHub repository gogs/gogs prior to 0.12.9.EPSS 4.5%9.8CVE-2019-14544Gogs missing authorization vulnerabilityroutes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks.EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2022-2024), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.