References https://www.sentinelone.com/vulnerability-database/cve-2022-0415/ https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0415.yaml https://pentest-tools.com/vulnerabilities-exploits/gogs-0126-remote-command-execution_3192 https://pentesterlab.com/exercises/cve-2022-0415 https://www.miggo.io/vulnerability-database/cve/CVE-2022-0415 https://github.com/cokeBeer/go-cves/blob/main/CVE-2022-0415/CVE-2022-0415.md https://cn-sec.com/archives/994701.html https://tttang.com/archive/1607/ https://mnihyc.com/blog/archives/1814 https://elvis.hk/aggregator/sources/146
Related VulnerabilitiesPoCCVE-2026-52806: Gogs <= 0.14.2 - Authenticated RCE via git rebase Argument InjectionGogs /api/v1/orgs/:orgname/teams 信息泄露漏洞(CVE-2026-52815)PoCCVE-2026-52815: Gogs < 0.14.3 - Unauthenticated Organization Teams DisclosureGogs Gogs 未授权 命令注入漏洞PoCCVE-2025-8110: Gogs <= 0.13.3 - Remote Code ExecutionPoCCVE-2014-8682: Gogs (Go Git Service) - SQL InjectionPoCCVE-2018-18925: Gogs (Go Git Service) 0.11.66 - Remote Code ExecutionPoCCVE-2020-15867: Gogs 0.5.5 - 0.12.2 - Remote Code ExecutionPoCCVE-2022-0415: Gogs <0.12.6 - Remote Command ExecutionPoCCVE-2022-0870: Gogs <0.12.5 - Server-Side Request ForgeryPoCgogs-installer: Gogs (Go Git Service) - Installer