CVE-2026-52798

Gogs is an open source self-hosted Git service. Prior to 0.14.3, although .ipynb previews are sanitized on the server side via /-/api/sanitize_ipynb, the inserted content is re-rendered on the client side without sanitization using marked() on elements with the .nb-markdown-cell class. During this process, links containing schemes such as javascript: can be regenerated. As a result, when a victim views an attacker-crafted .ipynb file and clicks the link, arbitrary JavaScript is executed in the Gogs origin, leading to a click-based Stored XSS. This vulnerability is fixed in 0.14.3.
Configurations

No configuration.

History

25 Jun 2026, 18:16

Type Values Removed Values Added
References () https://github.com/gogs/gogs/security/advisories/GHSA-jq8v-rmf6-65jw - () https://github.com/gogs/gogs/security/advisories/GHSA-jq8v-rmf6-65jw -

24 Jun 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-24 21:16

Updated : 2026-06-25 18:16


NVD link : CVE-2026-52798

Mitre link : CVE-2026-52798

CVE.ORG link : CVE-2026-52798


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')