Vulnerability record · CVE-2024-55947 · published 23 December 2024
CVE-2024-55947: Gogs path traversal allows arbitrary file write and SSH access
Gogs · Gogs
Gogs, a self-hosted Git service, is vulnerable to path traversal (CWE-22) that lets a malicious user write a file to an arbitrary path on the server. Because the write is unrestricted, an attacker can place an SSH key or similar file and gain SSH access to the host. The flaw is fixed in version 0.13.1.
Description
Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the server to gain SSH access to the server. The vulnerability is fixed in 0.13.1.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
high priorityCVSS 4.0 score of 8.7 with high confidentiality, integrity and availability impact, public exploit information, and very high EPSS, but exploitation requires an authenticated low-privilege account and the CVE is not in KEV.
What it is
Gogs, a self-hosted Git service, is vulnerable to path traversal (CWE-22) that lets a malicious user write a file to an arbitrary path on the server. Because the write is unrestricted, an attacker can place an SSH key or similar file and gain SSH access to the host. The flaw is fixed in version 0.13.1.
Impact
An attacker with a valid low-privilege account can write files anywhere on the server and use that to obtain SSH access, effectively compromising the underlying host and any data or services it holds.
Attack surface
The vulnerability is network-reachable (AV:N) with low attack complexity and no user interaction, but requires the attacker to hold a low-privilege authenticated account (PR:L). No special conditions beyond that account are described.
Exploitation
The vendor advisory is tagged Exploit, indicating public exploit information exists, and EPSS is very high (0.752, 99.5th percentile), though the CVE is not listed in CISA KEV. No ransomware usage is documented.
What to do
- Upgrade Gogs to 0.13.1 or later, which contains the fix.
- If immediate upgrade is not possible, restrict or disable untrusted user accounts and review repository/file write permissions.
- Run Gogs with a dedicated low-privilege service account and limit its filesystem write scope.
- Harden SSH on the host: disable password auth, restrict authorized_keys locations, and monitor for unexpected key additions.
- Audit the server filesystem for unexpected files or SSH keys written by Gogs processes.
Detection
- Monitor Gogs application logs for file write operations to paths outside expected repository or data directories.
- Alert on new or modified authorized_keys files and other SSH credential files on hosts running Gogs.
- Watch for unexpected outbound SSH connections or logins originating from the Gogs host.
- Review filesystem integrity monitoring (FIM) alerts for writes by the Gogs service account to system or home directories.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/gogs/gogs/commit/9a9388ace25bd646f5098cb9193d983332c34e41 | Patch |
| https://github.com/gogs/gogs/issues/7582 | Issue Tracking |
| https://github.com/gogs/gogs/pull/7859 | Patch |
| https://github.com/gogs/gogs/security/advisories/GHSA-qf5v-rp47-55gg | ExploitVendor Advisory |
| https://github.com/gogs/gogs/security/advisories/GHSA-qf5v-rp47-55gg | ExploitVendor Advisory |
Track CVE-2024-55947 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-55947), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.