
Remote Code Execution Vulnerability Discovered in Gogs Self-Hosted Git Service
Aikido's security researcher Jurriaan, collaborating with AI penetration testing agents, discovered a remote code execution vulnerability in Gogs, a self-hosted Git service. The AI agent initially found a path traversal vulnerability in the organization name creation process, where the API accepted dot-dot-slash sequences that were rejected by the web interface, allowing attackers to create repositories in arbitrary filesystem locations. While this primitive only created bare Git repositories with uncontrollable metadata files, Jurriaan combined it with a second primitive: the ability to create files through the UI in a specific location. By creating a nested Git repository structure—placing a bare repository inside another repository's work tree using path traversal—he could edit the inner repository's Git hooks through the outer repository. This allowed writing a malicious post-receive hook that executes arbitrary code whenever data is pushed to the repository, achieving remote code execution accessible to any user who can create an account on a Gogs instance. The vulnerability has been reported to Gogs and has been fixed.