Vulnerability record · CVE-2022-2024 · published 25 February 2023
CVE-2022-2024: Gogs OS command injection before 0.12.11
Gogs · Gogs
Gogs, a self-hosted Git service, contains an OS command injection flaw (CWE-78) in versions prior to 0.12.11. The CVSS 3.1 vector rates it 9.8 critical with network reachability, no privileges and no user interaction, so a remote attacker can run operating system commands on the host. The record does not name the specific vulnerable endpoint or parameter.
Description
OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, combined with a 99.9th percentile EPSS score and a public exploit reference, makes this an urgent patch.
What it is
Gogs, a self-hosted Git service, contains an OS command injection flaw (CWE-78) in versions prior to 0.12.11. The CVSS 3.1 vector rates it 9.8 critical with network reachability, no privileges and no user interaction, so a remote attacker can run operating system commands on the host. The record does not name the specific vulnerable endpoint or parameter.
Impact
An attacker can execute arbitrary operating system commands with the privileges of the Gogs process, leading to full compromise of the server and any data or credentials it holds. Because the vector shows high confidentiality, integrity and availability impact, expect complete loss of control over the instance.
Attack surface
Reachable over the network per the AV:N vector, with no authentication (PR:N) and no user interaction (UI:N) required. The description does not identify the exact request path or input field, so the precise entry point is unknown from this record.
Exploitation
Not listed in CISA KEV, but EPSS is 0.97839 (99.9th percentile), indicating very high predicted exploitation activity. A public exploit reference is tagged on the huntr.dev bounty, and a patch commit is available.
What to do
- Upgrade Gogs to 0.12.11 or later, applying the patch commit 15d0d6a94be0098a8227b6b95bdf2daed105ec41.
- If immediate upgrade is not possible, restrict network access to the Gogs instance to trusted users and networks only.
- Run the Gogs service under a low-privilege dedicated account with no unnecessary filesystem or shell access.
- Monitor the Gogs host for unexpected child processes or shell invocations spawned by the Gogs service.
Detection
- Alert on process creation events where the Gogs service account spawns shells (sh, bash, cmd, powershell) or unexpected binaries.
- Inspect Gogs HTTP access logs for requests containing shell metacharacters (;, |, $(), backticks) in parameters.
- Baseline normal Gogs child processes and flag deviations, especially outbound connections from the Gogs host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-2024 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-2024), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.