CVE detail
CVE-2022-1884 — CVE-2022-1884
Published 2024-11-15 · Modified 2026-06-17 · Vendor gogs · Product gogs · Source nvd
CRITICAL
severity
CVSS-derived band
0.0177
EPSS probability
exploitation probability, 30d
76.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to improper validation of the `tree_path` parameter during file uploads. An attacker can set `tree_path=.git.` to upload a file into the .git directory, allowing them to write or rewrite the `.git/config` file. If the `core.sshCommand` is set, this can lead to remote command execution.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References