CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-744x-3838-5r56: Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API

mediumCVE-2026-52815
Summary Gogs has an unauthenticated information disclosure vulnerability. The GET /api/v1/orgs/:orgname/teams endpoint at internal/route/api/v1/org_team.go:8 returns all teams for any organization without requiring authentication. The route group at internal/route/api/v1/api.go:380-385 lacks the reqToken() middleware, and the listTeams() handler performs no authentication check, exposing team IDs, names, descriptions, and permission levels to any unauthenticated caller. Affected Versions Gogs (all current versions) Vulnerability Details Root Cause: Missing reqToken() middleware on org teams route group internal/route/api/v1/api.go lines 380-385: // Org teams route group — no reqToken() middleware m.Group("/:orgname", func() { m.Get("/teams", org.ListTeams) // No auth required }, orgAssignment(true)) The orgAssignment(true) middleware only loads the organization object — it performs no authentication. The listTeams() handler at org_team.go:8 returns all teams unconditionally: func ListTeams(c *context.APIContext) { org := c.Org.Organization teams, err := database.GetTeamsByOrgID(org.ID) // Returns all teams — no c.IsLogged check, no permission check } Compare with other org endpoints that correctly require authentication: m.Group("/orgs/:orgname", func() { // ... other endpoints ... }, reqToken(), orgAssignment(true, true)) // reqToken() enforces auth Attack Chain - Attacker sends GET /api/v1/orgs/target-org/teams with no authentication - orgAssignment(true) loads the organization but does not check auth - ListTeams() queries all teams and returns them - Response includes team IDs, names, descriptions, and permission levels (read/write/admin/owner) Proof of Concept List all teams in an organization — no authentication needed curl -s "http://TARGET:3000/api/v1/orgs/myorg/teams" | python3 -m json.tool Expected: 200 OK with full team list [ { "id": 1, "name": "Owners", "description": "Admin team", "permission": "owner" }, { "id": 2, "name": "backend-devs

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
medium
Published
2026-06-23
Last updated
2026-07-21
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-744x-3838-5r56

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-52815coverage & exploitation statusNVD · CVE.org

More from GitHub Security Advisories