Cross-site scripting in gogs - CVE-2026-26276
Published: April 27, 2026
gogs
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in the victim's browser and disclose sensitive information or perform unauthorized actions.
The vulnerability exists due to cross-site scripting in milestone selection on the New Issue page when rendering a repository's milestone name. A remote user can store a crafted HTML/JavaScript payload in a milestone name to execute arbitrary script in the victim's browser and disclose sensitive information or perform unauthorized actions.
User interaction is required when another user selects the crafted milestone on /issues/new.