Cross-site scripting in gogs - CVE-2026-26195
Published: April 27, 2026
gogs
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in a user's browser.
The vulnerability exists due to cross-site scripting in branch and wiki views when rendering author and committer names in affected pages. A remote user can inject crafted commit metadata to execute arbitrary script in a user's browser.
Exploitation requires the ability to inject commit metadata such as an author or committer name.