CVE-2026-24135 | Gogs up to 0.13.3 updateWikiPage old_title path traversal (GHSA-jp7c-wj6q-3qf2 / WID-SEC-2026-0338)
A vulnerability marked as critical has been reported in Gogs up to 0.13.3. Affected by this issue is the function updateWikiPage. This manipulation of the argument old_title causes path traversal.
The identification of this vulnerability is CVE-2026-24135. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.