{"id":"CVE-2024-54148","aliases":["GHSA-r7j8-5h9c-f6fx","GO-2024-3355"],"url":"https://o3.security/vulnerability/CVE-2024-54148","summary":"Gogs has a Path Traversal in file editing UI","details":"Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a repository to gain SSH access to the server. The vulnerability is fixed in 0.13.1.","published":"2024-12-23T15:22:48.244Z","modified":"2026-08-08T03:47:50.698141689Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"gogs.io/gogs","fixedVersion":"0.13.1"}],"fix":{"url":"https://github.com/gogs/gogs/commit/c94baec9ca923f38c19f0c7c5af722b9ec04022a","label":"gogs/gogs@c94baec"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/54xxx/CVE-2024-54148.json"},{"type":"ADVISORY","url":"https://github.com/gogs/gogs/security/advisories/GHSA-r7j8-5h9c-f6fx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-54148"},{"type":"REPORT","url":"https://github.com/gogs/gogs/issues/7582"},{"type":"FIX","url":"https://github.com/gogs/gogs/commit/c94baec9ca923f38c19f0c7c5af722b9ec04022a"},{"type":"FIX","url":"https://github.com/gogs/gogs/pull/7857"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:47:50.698141689Z"}}