Cross-site scripting in gogs - CVE-2026-52807
Published: June 19, 2026
gogs
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary JavaScript in a victim's browser session.
The vulnerability exists due to cross-site scripting in the milestone dropdown on the new issue page when rendering a stored milestone name and processing dropdown interaction. A remote user can create a milestone with a crafted HTML/JavaScript payload to execute arbitrary JavaScript in a victim's browser session.
User interaction is required with the milestone dropdown on the new issue page.