CVE-2024-39930: Gogs
Critical severity, CVSS 9.9. EPSS: 7.7% chance of exploitation in the next 30 days.
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated attackers can exploit this by opening an SSH connection and sending a malicious --split-string env request if the built-in SSH server is activated. Windows installations are unaffected.
Affected products
- Gogs Gogs: up to and including 0.13.0
Published 2024-07-04. Last modified 2026-06-17.