### [CVE-2022-0415](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0415) ![](https://img.shields.io/static/v1?label=Product&message=gogs%2Fgogs&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=%3C%200.12.6%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-20%20Improper%20Input%20Validation&color=brighgreen) ### Description Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6. ### POC #### Reference - https://huntr.dev/bounties/b4928cfe-4110-462f-a180-6d5673797902 #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/bfengj/CTF - https://github.com/cokeBeer/go-cves - https://github.com/saveworks/saveworks - https://github.com/wuhan005/wuhan005