CVE-2026-25120
19.02.2026, 07:17
Gogs is an open source self-hosted Git service. In versions 0.13.4 and below, the DeleteComment API does not verify that the comment belongs to the repository specified in the URL. This allows a repository administrator to delete comments from any other repository by supplying arbitrary comment IDs, bypassing authorization controls. The DeleteComment function retrieves a comment by ID without verifying repository ownership and the Database function DeleteCommentByID performs no repository validation. This issue has been fixed in version 0.14.0.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gogs | gogs | 𝑥 < 0.14.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration