Cross-site request forgery in gogs - CVE-2026-52800
Published: June 19, 2026
gogs
Detailed vulnerability description
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to cross-site request forgery in the organization team member management endpoints when handling crafted GET requests to state-changing routes. A remote attacker can trick an organization owner into visiting a crafted link to escalate privileges.
User interaction is required, and the victim must be logged in as an organization owner.