GHSA-5qhx-gwfj-6jqr

Suggest an improvement
Source
https://github.com/advisories/GHSA-5qhx-gwfj-6jqr
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-5qhx-gwfj-6jqr/GHSA-5qhx-gwfj-6jqr.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-5qhx-gwfj-6jqr
Aliases
Published
2026-02-06T18:10:05Z
Modified
2026-02-19T20:56:08Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
Gogs user can update repository content with read-only permission
Details

Vulnerability Description

The endpoint PUT /repos/:owner/:repo/contents/* does not require write permissions and allows access with read permission only via repoAssignment().

After passing the permission check, PutContents() invokes UpdateRepoFile(), which results in:

  • Commit creation
  • Execution of git push

As a result, a token with read-only permission can be used to modify repository contents.


Attack Prerequisites

  • Possession of a valid access token
  • Read permission on the target repository (public repository or collaborator with read access)

Attack Scenario

  1. The attacker accesses the target repository with a read-only token
  2. The attacker sends a PUT /contents request to update an arbitrary file
  3. The server creates a commit and performs a git push on behalf of the attacker

Potential Impact

  • Source code tampering
  • Injection of backdoors
  • Compromise of release artifacts and distributed packages
Database specific
{
    "cwe_ids": [
        "CWE-862",
        "CWE-863"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-02-06T18:10:05Z",
    "nvd_published_at": "2026-02-06T18:15:56Z",
    "severity": "MODERATE"
}
References

Affected packages

Go / gogs.io/gogs

Package

Name
gogs.io/gogs
View open source insights on deps.dev
Purl
pkg:golang/gogs.io/gogs

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.13.4

Database specific

last_known_affected_version_range
"<= 0.13.3"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-5qhx-gwfj-6jqr/GHSA-5qhx-gwfj-6jqr.json"