{"id":"CVE-2026-26022","aliases":["GHSA-xrcr-gmf5-2r8j","GO-2026-4620"],"url":"https://o3.security/vulnerability/CVE-2026-26022","summary":"Gogs: Stored XSS via data URI in issue comments","details":"### Summary\nA Stored Cross-site Scripting (XSS) vulnerability exists in the comment and issue description functionality. The application's HTML sanitizer explicitly allows `data:` URI schemes, enabling authenticated users to inject arbitrary JavaScript execution via malicious links.\n\n### Details\nThe vulnerability is located in `internal/markup/sanitizer.go`. The application uses the `bluemonday` HTML sanitizer but explicitly weakens the security policy by allowing the `data` URL scheme:\n\n```go\n// internal/markup/sanitizer.go\nfunc NewSanitizer() {\n    sanitizer.init.Do(func() {\n        // ...\n        // Data URLs\n        sanitizer.policy.AllowURLSchemes(\"data\")\n        // ...\n    })\n}\n```\n\nWhile the Markdown renderer rewrites relative links (mitigating standard Markdown `[link](data:...)` attacks), Gogs supports **Raw HTML** input. Raw HTML anchor tags bypass the Markdown parser's link rewriting and are processed directly by the sanitizer. Since the sanitizer is configured to allow `data:` URIs, payloads like `<a href=\"data:text/html...\">` are rendered as-is.\n\n### PoC\n1.  Create a file named `exploit.md` in a repository.\n2.  Add the following content (Raw HTML):\n    ```html\n    <a href=\"data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4=\">Click me for XSS</a>\n    ```\n3.  Commit and push the file.\n4.  Navigate to the file in the Gogs web interface.\n5.  Click the \"Click me for XSS\" link.\n6.  **Result:** An alert box with \"XSS\" appears, executing the JavaScript payload.\n\n### Impact\nThis is a **Stored XSS** vulnerability. Any user who views the malicious comment and clicks the link will execute the attacker-supplied JavaScript in their browser context. This allows attackers to:\n*   Steal authentication cookies and session tokens.\n*   Perform arbitrary actions on behalf of the victim (e.g., modifying repositories, adding collaborators).\n*   Redirect users to malicious sites.","published":"2026-03-05T18:34:12.843Z","modified":"2026-08-12T03:51:10.957695868Z","cvss":{"score":8.7,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"gogs.io/gogs","fixedVersion":"0.14.2"}],"fix":{"url":"https://github.com/gogs/gogs/commit/441c64d7bd8893b2f4e48660a8be3a7472e14291","label":"gogs/gogs@441c64d"},"references":[{"type":"WEB","url":"https://github.com/gogs/gogs/releases/tag/v0.14.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26022.json"},{"type":"ADVISORY","url":"https://github.com/gogs/gogs/security/advisories/GHSA-xrcr-gmf5-2r8j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26022"},{"type":"FIX","url":"https://github.com/gogs/gogs/commit/441c64d7bd8893b2f4e48660a8be3a7472e14291"},{"type":"FIX","url":"https://github.com/gogs/gogs/pull/8174"},{"type":"PACKAGE","url":"https://github.com/gogs/gogs"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:10.957695868Z"}}