Critical severity9.9NVD Advisory· Published Jul 4, 2024· Updated Jun 17, 2026
CVE-2024-39932
CVE-2024-39932
Description
Gogs through 0.13.0 allows argument injection during the previewing of changes.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
gogs.io/gogsGo | < 0.13.1 | 0.13.1 |
Affected products
3Patches
Vulnerability mechanics
References
6- www.sonarsource.com/blog/securing-developer-tools-unpatched-code-vulnerabilities-in-gogs-1/nvdExploitMitigationThird Party Advisory
- github.com/advisories/GHSA-9pp6-wq8c-3w2cghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-39932ghsaADVISORY
- github.com/gogs/gogs/releasesnvdRelease Notes
- github.com/gogs/gogs/security/advisories/GHSA-9pp6-wq8c-3w2cghsaWEB
- www.sonarsource.com/blog/securing-developer-tools-unpatched-code-vulnerabilities-in-gogs-1ghsaWEB
News mentions
3- Gogs patches critical zero-day enabling remote code executionBleepingComputer · Jun 8, 2026
- New Gogs zero-day flaw lets hackers get remote code executionBleepingComputer · May 28, 2026
- CVE-2026-52806: Authenticated RCE via Argument Injection in Gogs (FIXED as of June 7, 2026)Rapid7 Blog · May 28, 2026