{"id":"CVE-2026-24135","aliases":["GHSA-jp7c-wj6q-3qf2","GO-2026-4452"],"url":"https://o3.security/vulnerability/CVE-2026-24135","summary":"Gogs vulnerable to arbitrary file deletion via path traversal in wiki page update","details":"Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, a path traversal vulnerability exists in the updateWikiPage function of Gogs. The vulnerability allows an authenticated user with write access to a repository's wiki to delete arbitrary files on the server by manipulating the old_title parameter in the wiki editing form. This issue has been patched in versions 0.13.4 and 0.14.0+dev.","published":"2026-02-06T17:47:49.935Z","modified":"2026-08-12T03:51:32.201130027Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"gogs.io/gogs","fixedVersion":"0.13.4"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24135.json"},{"type":"ADVISORY","url":"https://github.com/gogs/gogs/security/advisories/GHSA-jp7c-wj6q-3qf2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24135"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:32.201130027Z"}}