{"id":"GHSA-wv27-2vqp-j7g5","summary":"Gogs has the ability to import local repositories via Mirror Settings","details":"### Summary\nThe Gogs Mirror Settings functionality provide an alternative way from the well protected New Migration functionality for any authenticated users to import local repositories. This issue stems from a lack of validation of SaveAddress function.\n\n### Details\nHere is the function implementation of the secure New Migration functionality.\n\u003cimg width=\"1200\" height=\"755\" alt=\"image\" src=\"https://github.com/user-attachments/assets/a6c2f307-715e-4451-bbc1-7bd934d56f96\" /\u003e\n\nHere is the function implementation of the Mirror Settings without any validation.\n\u003cimg width=\"1200\" height=\"477\" alt=\"image\" src=\"https://github.com/user-attachments/assets/a11c41b8-1d08-499c-bce6-ab40844211d7\" /\u003e\n\n### PoC\nThe New Migration feature correctly blocked my attempt to import a local repository.\n\u003cimg width=\"1200\" height=\"1008\" alt=\"image\" src=\"https://github.com/user-attachments/assets/dfc5aa3f-1cc4-427d-b7fe-274363c83c4e\" /\u003e\n\nBut if I create a normal migration with a valid repository.\n\u003cimg width=\"1200\" height=\"1006\" alt=\"image\" src=\"https://github.com/user-attachments/assets/c96b356e-8ca9-4e79-a69b-ff14593c0cac\" /\u003e\n\nThen, I could use the Mirror Settings feature under the Repository Settings sync a local repository.\n\u003cimg width=\"1200\" height=\"476\" alt=\"image\" src=\"https://github.com/user-attachments/assets/9105475c-ae68-4d93-96d5-a3ec356deba7\" /\u003e\n\nHere is the result after the sync.\n\u003cimg width=\"1200\" height=\"533\" alt=\"image\" src=\"https://github.com/user-attachments/assets/1df76642-3e55-4493-a422-f7f0619b463d\" /\u003e\n\n\n### Impact\nUsers can import local repositories from the server's filesystem, which allows accessing any repository the git user has access to. There is also a potential issue of blind SSRF.","aliases":["CVE-2026-52801","GO-2026-5724"],"modified":"2026-07-21T13:45:22.975913499Z","published":"2026-06-23T00:03:43Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-06-23T00:03:43Z","nvd_published_at":"2026-06-24T21:16:55Z","cwe_ids":["CWE-20"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/gogs/gogs/security/advisories/GHSA-wv27-2vqp-j7g5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-52801"},{"type":"WEB","url":"https://github.com/gogs/gogs/pull/8225"},{"type":"WEB","url":"https://github.com/gogs/gogs/commit/11e19f28b5c82466fd1689c94344ef4313ee986c"},{"type":"PACKAGE","url":"https://github.com/gogs/gogs"},{"type":"WEB","url":"https://github.com/gogs/gogs/releases/tag/v0.14.3"}],"affected":[{"package":{"name":"gogs.io/gogs","ecosystem":"Go","purl":"pkg:golang/gogs.io/gogs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.14.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-wv27-2vqp-j7g5/GHSA-wv27-2vqp-j7g5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"}]}