← Back to browse · API

CVE-2024-39930

Severity
CRITICAL
CVSS
9.9
EPSS
0.07743
Risk score
42.31
CISA KEV
No
PoC
No
Published
2024-07-04
Modified
2024-08-28
First seen
2026-08-07
Aliases
EUVD-2024-3615, GHSA-VM62-9JW3-C8W3
Products
n/a:n/a n/a
Sources
euvd EUVD-2024-3615

Description

The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated attackers can exploit this by opening an SSH connection and sending a malicious --split-string env request if the built-in SSH server is activated. Windows installations are unaffected.

References