[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2024-54148":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T08:55:32.481Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":51,"aliases":61,"duplicate_of":9,"upstream":64,"downstream":65,"duplicates":70,"related":71,"reserved_at":9,"published_at":74,"modified_at":75,"state":76,"summary":77,"references_raw":85,"kevs":121,"epss":122,"epss_history":125,"metrics":379,"affected":395},"CVE-2024-54148","Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a repository to gain SSH access to the server. The vulnerability is fixed in 0.13.1.",null,[11,40],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-22","Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.","weakness","Stable","Base","High",[20,24,28,32,36],{"id":21,"name":22,"techniques":23},"CAPEC-126","Path Traversal",[],{"id":25,"name":26,"techniques":27},"CAPEC-64","Using Slashes and URL Encoding Combined to Bypass Validation Logic",[],{"id":29,"name":30,"techniques":31},"CAPEC-76","Manipulating Web Input to File System Calls",[],{"id":33,"name":34,"techniques":35},"CAPEC-78","Using Escaped Slashes in Alternate Encoding",[],{"id":37,"name":38,"techniques":39},"CAPEC-79","Using Slashes in Alternate Encoding",[],{"_key":41,"id":41,"name":42,"description":43,"type":15,"status":44,"abstraction":45,"likelihood_of_exploit":18,"capec":46},"CWE-61","UNIX Symbolic Link (Symlink) Following","The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.","Incomplete","Compound",[47],{"id":48,"name":49,"techniques":50},"CAPEC-27","Leveraging Race Conditions via Symbolic Links",[],[52],{"_key":53,"name":54,"source":55,"url":56,"maturity":57,"reliability_score":58,"verified":59,"type":9,"platforms":60,"requires_auth":9,"exploitdb":9,"metasploit":9},"GITHUB_GOGS_GOGS","Gogs","github","https://github.com/gogs/gogs/issues/5364","poc",0.3,false,[],[62,63],"GHSA-r7j8-5h9c-f6fx","GO-2024-3355",[],[66,68],{"_key":67},"SUSE-SU-2025:0060-1",{"_key":69},"OPENSUSE-SU-2025:14624-1",[],[72,73],{"_key":67},{"_key":69},"2024-12-23T15:22:48.244Z","2024-12-24T01:52:58.173Z","Analyzed",{"cisa_kev":59,"cisa_ransomware":59,"cisa_vendor":9,"epss_severity":78,"epss_score":79,"severity":80,"severity_score":81,"severity_version":82,"severity_source":83,"severity_vector":84,"severity_status":76},"low",0.00972,"critical",9.8,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",[86,97,103,108,112,116],{"url":87,"sources":88,"tags":91},"https://github.com/gogs/gogs/security/advisories/GHSA-r7j8-5h9c-f6fx",[83,89,90],"nvd","osv_go",[92,93,94,95,96],"X Refsource CONFIRM","Exploit","Vendor Advisory","WEB","Advisory",{"url":98,"sources":99,"tags":100},"https://github.com/gogs/gogs/issues/7582",[83,89,90],[101,102,95],"X Refsource MISC","Issue Tracking",{"url":104,"sources":105,"tags":106},"https://github.com/gogs/gogs/pull/7857",[83,89,90],[101,107,95],"Patch",{"url":109,"sources":110,"tags":111},"https://github.com/gogs/gogs/commit/c94baec9ca923f38c19f0c7c5af722b9ec04022a",[83,89,90],[101,107,95],{"url":113,"sources":114,"tags":115},"https://nvd.nist.gov/vuln/detail/CVE-2024-54148",[90],[96],{"url":117,"sources":118,"tags":119},"https://github.com/gogs/gogs",[90],[120],"PACKAGE",[],{"date":123,"score":79,"percentile":124},"2026-06-04",0.76989,[126,130,133,136,138,140,143,145,148,151,154,157,160,163,166,170,173,176,179,181,184,187,189,191,194,196,199,201,204,207,209,212,214,216,218,220,223,226,229,232,235,238,241,244,247,250,253,256,259,262,265,268,271,274,277,280,283,285,288,291,294,296,299,302,305,308,311,314,317,320,322,325,328,331,334,337,339,341,344,347,349,352,355,358,361,364,367,369,372,376],{"date":127,"score":128,"percentile":129},"2025-11-04",0.00823,0.73678,{"date":131,"score":128,"percentile":132},"2025-11-05",0.73663,{"date":134,"score":128,"percentile":135},"2025-11-06",0.7366,{"date":137,"score":128,"percentile":129},"2025-11-07",{"date":139,"score":128,"percentile":129},"2025-11-08",{"date":141,"score":128,"percentile":142},"2025-11-09",0.73673,{"date":144,"score":128,"percentile":135},"2025-11-10",{"date":146,"score":128,"percentile":147},"2025-11-11",0.73665,{"date":149,"score":128,"percentile":150},"2025-11-12",0.73684,{"date":152,"score":128,"percentile":153},"2025-11-13",0.73691,{"date":155,"score":128,"percentile":156},"2025-11-14",0.73698,{"date":158,"score":128,"percentile":159},"2025-11-15",0.73695,{"date":161,"score":128,"percentile":162},"2025-11-16",0.73692,{"date":164,"score":128,"percentile":165},"2025-11-17",0.73685,{"date":167,"score":168,"percentile":169},"2025-11-18",0.00854,0.72936,{"date":171,"score":168,"percentile":172},"2025-11-19",0.72944,{"date":174,"score":168,"percentile":175},"2025-11-20",0.72952,{"date":177,"score":128,"percentile":178},"2025-11-21",0.73704,{"date":180,"score":128,"percentile":159},"2025-11-22",{"date":182,"score":128,"percentile":183},"2025-11-23",0.7368,{"date":185,"score":128,"percentile":186},"2025-11-24",0.73675,{"date":188,"score":128,"percentile":129},"2025-11-25",{"date":190,"score":128,"percentile":150},"2025-11-26",{"date":192,"score":128,"percentile":193},"2025-11-27",0.73686,{"date":195,"score":128,"percentile":129},"2025-11-28",{"date":197,"score":128,"percentile":198},"2025-11-29",0.7367,{"date":200,"score":128,"percentile":147},"2025-11-30",{"date":202,"score":128,"percentile":203},"2025-12-01",0.73797,{"date":205,"score":128,"percentile":206},"2025-12-02",0.73803,{"date":208,"score":128,"percentile":206},"2025-12-03",{"date":210,"score":128,"percentile":211},"2025-12-04",0.73671,{"date":213,"score":128,"percentile":183},"2025-12-05",{"date":215,"score":128,"percentile":183},"2025-12-06",{"date":217,"score":128,"percentile":183},"2025-12-07",{"date":219,"score":128,"percentile":165},"2025-12-08",{"date":221,"score":128,"percentile":222},"2025-12-09",0.73716,{"date":224,"score":128,"percentile":225},"2025-12-10",0.73747,{"date":227,"score":128,"percentile":228},"2025-12-11",0.73764,{"date":230,"score":128,"percentile":231},"2025-12-12",0.73786,{"date":233,"score":128,"percentile":234},"2025-12-13",0.7379,{"date":236,"score":128,"percentile":237},"2025-12-14",0.73788,{"date":239,"score":128,"percentile":240},"2025-12-15",0.73792,{"date":242,"score":128,"percentile":243},"2025-12-16",0.73801,{"date":245,"score":128,"percentile":246},"2025-12-17",0.73813,{"date":248,"score":128,"percentile":249},"2025-12-18",0.73836,{"date":251,"score":128,"percentile":252},"2025-12-19",0.73852,{"date":254,"score":128,"percentile":255},"2025-12-20",0.7385,{"date":257,"score":128,"percentile":258},"2025-12-21",0.73842,{"date":260,"score":128,"percentile":261},"2025-12-22",0.73843,{"date":263,"score":128,"percentile":264},"2025-12-23",0.73833,{"date":266,"score":128,"percentile":267},"2025-12-24",0.73844,{"date":269,"score":128,"percentile":270},"2025-12-25",0.73871,{"date":272,"score":128,"percentile":273},"2025-12-26",0.73868,{"date":275,"score":128,"percentile":276},"2025-12-27",0.73896,{"date":278,"score":128,"percentile":279},"2025-12-28",0.73845,{"date":281,"score":128,"percentile":282},"2025-12-29",0.73838,{"date":284,"score":128,"percentile":252},"2025-12-30",{"date":286,"score":128,"percentile":287},"2025-12-31",0.73881,{"date":289,"score":128,"percentile":290},"2026-01-01",0.7403,{"date":292,"score":128,"percentile":293},"2026-01-02",0.74029,{"date":295,"score":128,"percentile":290},"2026-01-03",{"date":297,"score":128,"percentile":298},"2026-01-04",0.73894,{"date":300,"score":128,"percentile":301},"2026-01-05",0.73888,{"date":303,"score":128,"percentile":304},"2026-01-06",0.73903,{"date":306,"score":128,"percentile":307},"2026-01-07",0.73912,{"date":309,"score":128,"percentile":310},"2026-01-08",0.73925,{"date":312,"score":128,"percentile":313},"2026-01-09",0.73932,{"date":315,"score":128,"percentile":316},"2026-01-10",0.73927,{"date":318,"score":128,"percentile":319},"2026-01-11",0.73914,{"date":321,"score":128,"percentile":304},"2026-01-12",{"date":323,"score":128,"percentile":324},"2026-01-13",0.73902,{"date":326,"score":128,"percentile":327},"2026-01-14",0.73926,{"date":329,"score":128,"percentile":330},"2026-01-15",0.73937,{"date":332,"score":128,"percentile":333},"2026-01-16",0.73953,{"date":335,"score":128,"percentile":336},"2026-01-17",0.7395,{"date":338,"score":128,"percentile":327},"2026-01-18",{"date":340,"score":128,"percentile":319},"2026-01-19",{"date":342,"score":128,"percentile":343},"2026-01-20",0.73917,{"date":345,"score":128,"percentile":346},"2026-01-21",0.73921,{"date":348,"score":128,"percentile":327},"2026-01-22",{"date":350,"score":128,"percentile":351},"2026-01-23",0.73957,{"date":353,"score":128,"percentile":354},"2026-01-24",0.73966,{"date":356,"score":128,"percentile":357},"2026-01-25",0.73949,{"date":359,"score":128,"percentile":360},"2026-01-26",0.73947,{"date":362,"score":128,"percentile":363},"2026-01-27",0.73952,{"date":365,"score":128,"percentile":366},"2026-01-28",0.73965,{"date":368,"score":128,"percentile":366},"2026-01-29",{"date":370,"score":128,"percentile":371},"2026-01-30",0.73969,{"date":373,"score":374,"percentile":375},"2026-01-31",0.00718,0.71966,{"date":377,"score":374,"percentile":378},"2026-02-01",0.72091,[380,388,392],{"source":83,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":381,"cvss_v4_0":384},{"baseScore":81,"baseSeverity":382,"vectorString":84,"impactScore":81,"exploitabilityScore":383},"CRITICAL",10,{"baseScore":385,"baseSeverity":386,"vectorString":387,"impactScore":9,"exploitabilityScore":9},8.7,"HIGH","CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",{"source":89,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":389,"cvss_v4_0":390},{"baseScore":81,"baseSeverity":382,"vectorString":84,"impactScore":81,"exploitabilityScore":383},{"baseScore":385,"baseSeverity":386,"vectorString":391,"impactScore":9,"exploitabilityScore":9},"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",{"source":90,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":393,"cvss_v4_0":394},{"baseScore":81,"baseSeverity":9,"vectorString":84,"impactScore":81,"exploitabilityScore":383},{"baseScore":385,"baseSeverity":9,"vectorString":387,"impactScore":9,"exploitabilityScore":9},[396,404],{"ecosystem":9,"name":54,"vendor":9,"product":54,"cpe_part":9,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":397},[398],{"version":399,"is_range":400,"range_type":401,"version_start":9,"version_start_type":9,"version_end":402,"version_end_type":403,"fixed_in":9},"lt0.13.1",true,"cpe","0.13.1","excluding",{"ecosystem":405,"name":406,"vendor":407,"product":408,"cpe_part":9,"purl_type":409,"purl_namespace":407,"purl_name":408,"source":9,"versions":410},"Go","gogs.io/gogs","gogs.io","gogs","golang",[411],{"version":412,"is_range":400,"range_type":413,"version_start":9,"version_start_type":9,"version_end":402,"version_end_type":403,"fixed_in":9},"lt0_13_1","semver"]