Summary
CVE-2026-52799 is a missing authorization vulnerability in Gogs, an open-source self-hosted Git service, affecting all versions prior to 0.14.3. The GET /attachments/:uuid endpoint serves raw attachment files without verifying whether the requester holds view permission for the associated Issue, Comment, Release, or repository, allowing an attacker with knowledge of an attachment UUID to download files from private repositories. With a CVSS v3.1 score of 7.5 (High), the vulnerability carries no authentication or user-interaction requirement and results in a high confidentiality impact.
Technical details
- Root cause: The attachment download handler in
internal/cmd/web.goretrieves attachment records by UUID alone and returns the corresponding file without performing any authorization check. The underlying database function ininternal/database/attachment.goperforms no validation tied to repository visibility or user permissions (CWE-862: Missing Authorization; CWE-639: Authorization Bypass Through User-Controlled Key). - Trigger conditions: When
REQUIRE_SIGNIN_VIEW = false(the default in many self-hosted deployments), fully unauthenticated requests are sufficient. When sign-in is required, any logged-in user — even without repository access — can exploit the endpoint, as repository-level permissions are never enforced. - Attack vector: Remote, network-accessible HTTP request to
GET /attachments/:uuidwith no special privileges or user interaction; the only prerequisite is knowledge of a target attachment’s UUID. - Impact: Unauthorized disclosure of attachment files from private repositories, potentially including credentials, cryptographic keys, internal documents, unpublished source code, or personal data.
Affected software
- Gogs all versions prior to 0.14.3 (i.e., ≤ 0.14.2)
Severity
- CVSS v3.1 Base Score: 7.5 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate – upgrade: Update Gogs to version 0.14.3, which introduces proper authorization verification on the
GET /attachments/:uuidendpoint before serving any file. - If immediate patching is not possible:
- Set
REQUIRE_SIGNIN_VIEW = trueinapp.inito prevent unauthenticated access to all Gogs endpoints, raising the bar for exploitation. - Apply network-level controls (firewall rules, reverse-proxy access restrictions) to limit exposure of the Gogs instance to trusted networks only, preventing unauthenticated internet-facing access.
- Set
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

