{"id":"GHSA-4565-r4x7-hg8j","summary":"Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation","details":"## Summary\n\nA repository admin collaborator can escalate their privileges to owner-level access by exploiting an off-by-one error in the `ChangeCollaborationAccessMode` function.\n\n## Vulnerable Code\n\nIn `internal/database/repo_collaboration.go`, line 129:\n\n```go\nfunc (r *Repository) ChangeCollaborationAccessMode(userID int64, mode AccessMode) error {\n    // Discard invalid input\n    if mode \u003c= AccessModeNone || mode \u003e AccessModeOwner {\n        return nil\n    }\n```\n\n`AccessModeOwner` has value 4. The check `mode \u003e AccessModeOwner` evaluates to `4 \u003e 4 = false`, allowing `AccessModeOwner` to pass through. The correct check should be `mode \u003e= AccessModeOwner`.\n\nThe web route at `internal/route/repo/setting.go:413-416` takes the mode as a raw integer from query parameters:\n\n```go\nfunc ChangeCollaborationAccessMode(c *context.Context) {\n    if err := c.Repo.Repository.ChangeCollaborationAccessMode(\n        c.QueryInt64(\"uid\"),\n        database.AccessMode(c.QueryInt(\"mode\"))); err != nil {\n```\n\nThis allows an admin collaborator to POST `mode=4` and escalate to owner.\n\n## Impact\n\nA repository admin collaborator (AccessModeAdmin = 3) can escalate to owner-level access (AccessModeOwner = 4), gaining the ability to:\n- **Delete the repository**\n- **Transfer repository ownership** to another user\n- **Erase wiki data**\n- Perform all other owner-only operations\n\nThe `access` table is also updated (line 181), so the escalated permissions persist across sessions.\n\n## Contrast\n\nThe API route at `internal/route/api/v1/repo_collaborators.go:46` uses `ParseAccessMode()` which only returns Read, Write, or Admin - never Owner. The API endpoint is not affected.\n\n## Steps to Reproduce\n\n1. User A creates a private repository\n2. User A adds User B as a collaborator with **Admin** access (mode=3)\n3. User B logs in and navigates to the repository settings collaboration page\n4. User B sends a POST request:\n   ```\n   POST /{owner}/{repo}/settings/collaboration/access_mode?uid={B_uid}&mode=4\n   ```\n5. User B now has **Owner** access - the \"Danger Zone\" section appears with \"Delete This Repository\" and \"Transfer Ownership\" buttons\n\n## Suggested Fix\n\nChange the validation in `internal/database/repo_collaboration.go` line 129 from:\n```go\nif mode \u003c= AccessModeNone || mode \u003e AccessModeOwner {\n```\nto:\n```go\nif mode \u003c= AccessModeNone || mode \u003e= AccessModeOwner {\n```","aliases":["CVE-2026-52804","GO-2026-5110"],"modified":"2026-07-21T13:30:24.705935939Z","published":"2026-06-23T16:52:30Z","database_specific":{"github_reviewed_at":"2026-06-23T16:52:30Z","nvd_published_at":"2026-06-24T21:16:56Z","cwe_ids":["CWE-193"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/gogs/gogs/security/advisories/GHSA-4565-r4x7-hg8j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-52804"},{"type":"WEB","url":"https://github.com/gogs/gogs/pull/8227"},{"type":"WEB","url":"https://github.com/gogs/gogs/commit/1fdc9cc28e159135cfa4d6b11ecd5daa0f8ce22b"},{"type":"PACKAGE","url":"https://github.com/gogs/gogs"},{"type":"WEB","url":"https://github.com/gogs/gogs/releases/tag/v0.14.3"}],"affected":[{"package":{"name":"gogs.io/gogs","ecosystem":"Go","purl":"pkg:golang/gogs.io/gogs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.14.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-4565-r4x7-hg8j/GHSA-4565-r4x7-hg8j.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"}]}