Cross-site scripting in gogs - CVE-2026-26022
Published: April 27, 2026
gogs
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary JavaScript in a victim's browser context.
The vulnerability exists due to improper neutralization of script-related content in internal/markup/sanitizer.go when processing raw HTML links containing data: URIs in issue comments and descriptions. A remote user can inject a crafted link to execute arbitrary JavaScript in a victim's browser context.
User interaction is required, and the victim must click the crafted link.