CVE-2020-15867
Gogs vulnerability analysis and mitigation

Overview

The git hook feature in Gogs versions 0.5.5 through 0.12.2 contains a vulnerability that allows for authenticated remote code execution. The vulnerability can lead to privilege escalation if access to the git hook feature is granted to users without administrative privileges (CVE Details).

Technical details

The vulnerability is similar to CVE-2020-14144 found in Gitea (a fork of Gogs). When a user has permissions to create Git hooks, which is the default setting for administrators, they can execute code on the server through the web interface. This capability can also be granted to non-administrative users, making it a potential privilege escalation vector (AttackerKB).

Impact

The vulnerability allows authenticated users with git hook permissions to execute arbitrary code on the server. If the feature is granted to non-administrative users, it can be exploited for privilege escalation. The severity is reflected in its CVSS v3 Base Score of 7.2, with high impact scores for confidentiality, integrity, and availability (AttackerKB).

Exploitability

The vulnerability requires authentication and elevated access to exploit. A Metasploit module (exploit/multi/http/gogs_git_hooks_rce) is available for exploitation, making it relatively easy to weaponize despite requiring specific conditions (AttackerKB).

Mitigation and workarounds

The recommended mitigation is to set the DISABLE_GIT_HOOKS configuration setting to true, which completely disables the git hooks feature and prevents all users, including administrators, from creating custom Git hooks (AttackerKB).

Additional resources


SourceThis report was generated using AI

Related Gogs vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-26194HIGH8.8
  • Gogs logoGogs
  • gogs.io/gogs
NoYesMar 05, 2026
CVE-2026-26196MEDIUM6.9
  • Gogs logoGogs
  • gogs
NoYesMar 05, 2026
CVE-2026-26195MEDIUM6.9
  • Gogs logoGogs
  • gogs
NoYesMar 05, 2026
CVE-2026-26276MEDIUM5.4
  • Gogs logoGogs
  • gogs
NoYesMar 05, 2026
CVE-2026-26022MEDIUM5.4
  • Gogs logoGogs
  • gogs
NoYesMar 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management