{"document":{"category":"csaf_vex","csaf_version":"2.0","title":"CVE-2026-52797: Gogs: Overwriting critical files results in a denial of service","publisher":{"category":"vendor","name":"HarborGuard Database","namespace":"https://database.harborguard.co"},"tracking":{"id":"CVE-2026-52797","status":"final","version":"1","initial_release_date":"2026-06-24T20:35:09.235Z","current_release_date":"2026-06-25T12:37:15.049Z","revision_history":[{"date":"2026-06-24T20:35:09.235Z","number":"1","summary":"Initial machine-readable export from HarborGuard."}]},"distribution":{"tlp":{"label":"WHITE"},"text":"Public CVE data; freely redistributable."},"notes":[{"category":"description","text":"Gogs is an open source self-hosted Git service. Prior to 0.14.0, as an authorized user, an intruder can dictate the value which is passed to the git diff command which, together with bypassing the filtering of the passed value, allows the user to bypass the target directory and write the result of the comparison to any arbitrary path. This vulnerability is fixed in 0.14.0.","title":"CVE description"}],"references":[{"category":"self","summary":"CVE-2026-52797 on HarborGuard Database","url":"https://database.harborguard.co/cve/CVE-2026-52797"},{"category":"external","summary":"CVE Record","url":"https://www.cve.org/CVERecord?id=CVE-2026-52797"},{"category":"external","summary":"https://github.com/gogs/gogs/security/advisories/GHSA-pm6v-2h4w-4rp2","url":"https://github.com/gogs/gogs/security/advisories/GHSA-pm6v-2h4w-4rp2"}]},"product_tree":{"branches":[{"category":"vendor","name":"gogs","branches":[{"category":"product_name","name":"gogs","branches":[{"category":"product_version","name":"< 0.14.0","product":{"name":"gogs gogs < 0.14.0","product_id":"CSAFPID-1","product_identification_helper":{"cpe":"cpe:2.3:a:gogs:gogs:\\<_0.14.0:*:*:*:*:*:*:*"}}}]}]}]},"vulnerabilities":[{"cve":"CVE-2026-52797","title":"Gogs: Overwriting critical files results in a denial of service","notes":[{"category":"description","text":"Gogs is an open source self-hosted Git service. Prior to 0.14.0, as an authorized user, an intruder can dictate the value which is passed to the git diff command which, together with bypassing the filtering of the passed value, allows the user to bypass the target directory and write the result of the comparison to any arbitrary path. This vulnerability is fixed in 0.14.0.","title":"CVE description"}],"product_status":{"known_affected":["CSAFPID-1"]},"scores":[{"cvss_v3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H","baseScore":8.5,"baseSeverity":"HIGH"},"products":["CSAFPID-1"]}],"remediations":[{"category":"none_available","details":"No fixed version is published yet. Monitor the upstream advisory.","product_ids":["CSAFPID-1"]}]}]}