{"id":"CVE-2026-52801","aliases":["GHSA-wv27-2vqp-j7g5","GO-2026-5724"],"url":"https://o3.security/vulnerability/CVE-2026-52801","summary":"Gogs: Ability to import local repositories via Mirror Settings","details":"### Summary\nThe Gogs Mirror Settings functionality provide an alternative way from the well protected New Migration functionality for any authenticated users to import local repositories. This issue stems from a lack of validation of SaveAddress function.\n\n### Details\nHere is the function implementation of the secure New Migration functionality.\n<img width=\"1200\" height=\"755\" alt=\"image\" src=\"https://github.com/user-attachments/assets/a6c2f307-715e-4451-bbc1-7bd934d56f96\" />\n\nHere is the function implementation of the Mirror Settings without any validation.\n<img width=\"1200\" height=\"477\" alt=\"image\" src=\"https://github.com/user-attachments/assets/a11c41b8-1d08-499c-bce6-ab40844211d7\" />\n\n### PoC\nThe New Migration feature correctly blocked my attempt to import a local repository.\n<img width=\"1200\" height=\"1008\" alt=\"image\" src=\"https://github.com/user-attachments/assets/dfc5aa3f-1cc4-427d-b7fe-274363c83c4e\" />\n\nBut if I create a normal migration with a valid repository.\n<img width=\"1200\" height=\"1006\" alt=\"image\" src=\"https://github.com/user-attachments/assets/c96b356e-8ca9-4e79-a69b-ff14593c0cac\" />\n\nThen, I could use the Mirror Settings feature under the Repository Settings sync a local repository.\n<img width=\"1200\" height=\"476\" alt=\"image\" src=\"https://github.com/user-attachments/assets/9105475c-ae68-4d93-96d5-a3ec356deba7\" />\n\nHere is the result after the sync.\n<img width=\"1200\" height=\"533\" alt=\"image\" src=\"https://github.com/user-attachments/assets/1df76642-3e55-4493-a422-f7f0619b463d\" />\n\n\n### Impact\nUsers can import local repositories from the server's filesystem, which allows accessing any repository the git user has access to. There is also a potential issue of blind SSRF.","published":"2026-06-24T20:18:55.465Z","modified":"2026-08-12T03:51:21.616239914Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"},"epss":{"score":0.00569,"percentile":0.45619,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"gogs.io/gogs","fixedVersion":"0.14.3"}],"fix":{"url":"https://github.com/gogs/gogs/commit/11e19f28b5c82466fd1689c94344ef4313ee986c","label":"gogs/gogs@11e19f2"},"references":[{"type":"WEB","url":"https://github.com/gogs/gogs/releases/tag/v0.14.3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/52xxx/CVE-2026-52801.json"},{"type":"ADVISORY","url":"https://github.com/gogs/gogs/security/advisories/GHSA-wv27-2vqp-j7g5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-52801"},{"type":"FIX","url":"https://github.com/gogs/gogs/commit/11e19f28b5c82466fd1689c94344ef4313ee986c"},{"type":"FIX","url":"https://github.com/gogs/gogs/pull/8225"},{"type":"PACKAGE","url":"https://github.com/gogs/gogs"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:21.616239914Z"}}