[{"uuid":"GSA_kwCzR0hTQS14aDMyLWN4NmMtY3A0ds4ABJZR","url":"https://github.com/advisories/GHSA-xh32-cx6c-cp4v","title":"Gogs XSS allowed by stored call in PDF renderer","description":"### Summary\n\nA stored XSS is present in Gogs which allows client-side Javascript code execution.\n\n### Details\n\nGogs Version:\n```\ndocker images\nREPOSITORY   TAG       IMAGE ID       CREATED        SIZE\ngogs/gogs    latest    fe92583bc4fe   10 hours ago   99.3MB\n```\n\nApplication version: `0.14.0+dev`\n\nLocal setup using:\n```bash\n# Pull image from Docker Hub.\ndocker pull gogs/gogs\n\n# Create local directory for volume.\nsudo mkdir -p /var/gogs\n\n# Use `docker run` for the first time.\ndocker run --name=gogs -p 10022:22 -p 10880:3000 -v /var/gogs:/data gogs/gogs\n```\n\nThe vulnerability is caused by the usage of a vulnerable and outdated component: `pdfjs-1.4.20` under public/plugins/.  \nRead more about this vulnerability at [codeanlabs - CVE-2024-4367](https://codeanlabs.com/blog/research/cve-2024-4367-arbitrary-js-execution-in-pdf-js/).\n\n### PoC\n\n1. Upload the Proof of Concept file hosted at https://codeanlabs.com/wp-content/uploads/2024/05/poc_generalized_CVE-2024-4367.pdf in a repository.\n2. Click on the file to be previewed.\n\n![poc](https://github.com/user-attachments/assets/5af1303e-8751-49c8-af2e-d0631dd18957)\n\n\n### Credits\n\nEdoardo Ottavianelli","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-06-26T16:54:01.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N","references":["https://github.com/gogs/gogs/security/advisories/GHSA-xh32-cx6c-cp4v","https://nvd.nist.gov/vuln/detail/CVE-2025-47943","https://github.com/gogs/gogs/commit/110117b2e5e5baa4809c819bec701e929d2d8d40","https://github.com/gogs/gogs/releases/tag/v0.13.3","https://www.hacktivesecurity.com/blog/2025/07/15/cve-2025-47943-stored-xss-in-gogs-via-pdf","https://github.com/advisories/GHSA-xh32-cx6c-cp4v"],"source_kind":"github","identifiers":["GHSA-xh32-cx6c-cp4v","CVE-2025-47943"],"repository_url":"https://github.com/gogs/gogs","blast_radius":0.0,"created_at":"2025-06-26T17:10:06.267Z","updated_at":"2026-10-11T03:07:53.100Z","epss_percentage":0.00386,"epss_percentile":0.305,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14aDMyLWN4NmMtY3A0ds4ABJZR","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS14aDMyLWN4NmMtY3A0ds4ABJZR","packages":[{"ecosystem":"go","package_name":"gogs.io/gogs","versions":[{"first_patched_version":"0.13.3-0.20250608224432-110117b2e5e5","vulnerable_version_range":"\u003c 0.13.3-0.20250608224432-110117b2e5e5"}],"purl":"pkg:go/gogs.io%2Fgogs"},{"ecosystem":"go","package_name":"github.com/gogs/gogs","versions":[{"first_patched_version":"0.13.3-0.20250608224432-110117b2e5e5","vulnerable_version_range":"\u003c 0.13.3-0.20250608224432-110117b2e5e5"}],"purl":"pkg:go/github.com%2Fgogs%2Fgogs"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14aDMyLWN4NmMtY3A0ds4ABJZR/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS04bW02LXdtcHAtbW1tM84AA9ly","url":"https://github.com/advisories/GHSA-8mm6-wmpp-mmm3","title":"Duplicate Advisory: Gogs allows argument injection during the tagging of a new release","description":"# Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-m27m-h5gj-wwmg. This link is maintained to preserve external references.\n\n# Original Description\nGogs through 0.13.0 allows argument injection during the tagging of a new release. This vulnerability is still unfixed as of the time of this advisory being published.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-07-04T18:31:11.000Z","withdrawn_at":"2024-12-23T20:36:50.000Z","classification":"GENERAL","cvss_score":8.2,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2024-39933","https://www.sonarsource.com/blog/securing-developer-tools-unpatched-code-vulnerabilities-in-gogs-1","https://github.com/gogs/gogs/releases","https://github.com/advisories/GHSA-8mm6-wmpp-mmm3"],"source_kind":"github","identifiers":["GHSA-8mm6-wmpp-mmm3"],"repository_url":"https://github.com/gogs/gogs","blast_radius":14.270974053852798,"created_at":"2024-07-05T21:05:27.428Z","updated_at":"2026-06-09T13:05:40.064Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04bW02LXdtcHAtbW1tM84AA9ly","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04bW02LXdtcHAtbW1tM84AA9ly","packages":[{"ecosystem":"go","package_name":"github.com/gogs/gogs","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003c= 0.13.0"}],"purl":"pkg:go/github.com%2Fgogs%2Fgogs"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04bW02LXdtcHAtbW1tM84AA9ly/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1oZjI5LTloZmgtdzYzas4AA9lz","url":"https://github.com/advisories/GHSA-hf29-9hfh-w63j","title":"Duplicate Advisory: Gogs allows argument injection during the previewing of changes","description":"# Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-9pp6-wq8c-3w2c. This link is maintained to preserve external references.\n\n# Original Description\nGogs through 0.13.0 allows argument injection during the previewing of changes.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2024-07-04T18:31:11.000Z","withdrawn_at":"2024-12-23T20:37:16.000Z","classification":"GENERAL","cvss_score":9.4,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2024-39932","https://www.sonarsource.com/blog/securing-developer-tools-unpatched-code-vulnerabilities-in-gogs-1","https://github.com/gogs/gogs/releases","https://github.com/advisories/GHSA-hf29-9hfh-w63j"],"source_kind":"github","identifiers":["GHSA-hf29-9hfh-w63j"],"repository_url":"https://github.com/gogs/gogs","blast_radius":16.359409281245892,"created_at":"2024-07-05T21:05:27.788Z","updated_at":"2026-06-09T13:05:40.065Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oZjI5LTloZmgtdzYzas4AA9lz","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1oZjI5LTloZmgtdzYzas4AA9lz","packages":[{"ecosystem":"go","package_name":"github.com/gogs/gogs","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003c= 0.13.0"}],"purl":"pkg:go/github.com%2Fgogs%2Fgogs"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oZjI5LTloZmgtdzYzas4AA9lz/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0ydmdqLTNwdmcteGg0d84AA9lx","url":"https://github.com/advisories/GHSA-2vgj-3pvg-xh4w","title":"Duplicate Advisory: Gogs allows deletion of internal files","description":"# Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-ccqv-43vm-4f3w. This link is maintained to preserve external references.\n\n# Original Description\nGogs through 0.13.0 allows deletion of internal files. ","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2024-07-04T18:31:10.000Z","withdrawn_at":"2024-12-23T20:37:05.000Z","classification":"GENERAL","cvss_score":9.4,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2024-39931","https://github.com/gogs/gogs/releases","https://www.sonarsource.com/blog/securing-developer-tools-unpatched-code-vulnerabilities-in-gogs-1","https://github.com/advisories/GHSA-2vgj-3pvg-xh4w"],"source_kind":"github","identifiers":["GHSA-2vgj-3pvg-xh4w"],"repository_url":"https://github.com/gogs/gogs","blast_radius":16.359409281245892,"created_at":"2024-07-05T21:05:27.825Z","updated_at":"2026-06-09T13:05:40.066Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0ydmdqLTNwdmcteGg0d84AA9lx","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0ydmdqLTNwdmcteGg0d84AA9lx","packages":[{"ecosystem":"go","package_name":"github.com/gogs/gogs","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003c= 0.13.0"}],"purl":"pkg:go/github.com%2Fgogs%2Fgogs"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0ydmdqLTNwdmcteGg0d84AA9lx/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1wNjlyLXYzaDQtcmo0Zs4AA9l1","url":"https://github.com/advisories/GHSA-p69r-v3h4-rj4f","title":"Duplicate Advisory: github.com/gogs/gogs affected by CVE-2024-39930","description":"# Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-vm62-9jw3-c8w3. This link is maintained to preserve external references.\n\n# Original Description\nThe built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated attackers can exploit this by opening an SSH connection and sending a malicious --split-string env request if the built-in SSH server is activated. Windows installations are unaffected.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2024-07-04T18:31:10.000Z","withdrawn_at":"2024-12-23T20:37:28.000Z","classification":"GENERAL","cvss_score":9.4,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2024-39930","https://github.com/gogs/gogs/releases","https://www.sonarsource.com/blog/securing-developer-tools-unpatched-code-vulnerabilities-in-gogs-1","https://www.vicarius.io/vsociety/posts/argument-injection-in-gogs-ssh-server-cve-2024-39930","https://github.com/advisories/GHSA-p69r-v3h4-rj4f"],"source_kind":"github","identifiers":["GHSA-p69r-v3h4-rj4f"],"repository_url":"https://github.com/gogs/gogs","blast_radius":16.359409281245892,"created_at":"2024-07-10T15:05:48.001Z","updated_at":"2026-06-09T13:05:38.708Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wNjlyLXYzaDQtcmo0Zs4AA9l1","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1wNjlyLXYzaDQtcmo0Zs4AA9l1","packages":[{"ecosystem":"go","package_name":"github.com/gogs/gogs","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003c= 0.13.0"}],"purl":"pkg:go/github.com%2Fgogs%2Fgogs"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wNjlyLXYzaDQtcmo0Zs4AA9l1/related_packages","related_advisories":[]}]