Security Digest: June 23, 2026 - 5 Critical Vulnerabilities

Five high-severity flaws are now public, and all of them can be abused quickly if exposed systems are left unpatched. The immediate risk is account takeover, unauthorized access to private data, and server-side abuse in widely deployed Gogs and Budibase installations.

· 7 min read

Executive Summary

Five high-severity flaws are now public, and all of them can be abused quickly if exposed systems are left unpatched. The immediate risk is account takeover, unauthorized access to private data, and server-side abuse in widely deployed Gogs and Budibase installations.

Act now: patch affected systems, restrict access to repository and organization management routes, and audit for suspicious downloads, repo changes, and automation activity.

Critical Vulnerabilities

  • CVE-2026-52798: Gogs .ipynb preview click-based stored XSS
    • Impact: An attacker can plant a malicious notebook link that executes JavaScript in the Gogs origin when clicked, enabling session abuse, token theft, and unauthorized actions.
    • Affected Systems: Gogs instances rendering .ipynb previews, including public or collaborator-writable repositories.
    • Immediate Action: Disable notebook preview exposure where possible, warn users not to open untrusted .ipynb files, and patch Gogs immediately.
    • Mitigation: Add client-side sanitization for re-rendered markdown, enforce CSP on preview pages, and remove or restrict preview rendering until fixed.
  • CVE-2026-52800: Gogs organization owner escalation via CSRF-free GET request
    • Impact: A logged-in organization owner can be tricked into adding an attacker to the Owners team, granting full org-owner privileges.
    • Affected Systems: Gogs 0.14.1 organization management routes that allow state changes via GET.
    • Immediate Action: Block or monitor crafted links to organization team-management endpoints and patch without delay.
    • Mitigation: Require POST for state changes, enforce CSRF on all membership actions, and review organization membership for unauthorized additions.
  • CVE-2026-54353: Budibase SSRF via DNS rebinding in outbound fetch
    • Impact: Authenticated users with automation permissions can make the server connect to internal services, loopback, RFC1918 ranges, and cloud metadata endpoints.
    • Affected Systems: Budibase installations using outbound fetch or automation steps that validate hostnames before fetch.
    • Immediate Action: Restrict automation permissions, block external DNS rebinding domains, and inspect outbound automation usage now.
    • Mitigation: Pin validated IPs to the socket connection, use a hardened HTTP agent, and rework blacklist checks to prevent TOCTOU DNS rebinding.
  • CVE-2026-52801: Gogs mirror settings allow local repository import
    • Impact: Authenticated users can bypass migration safeguards and import local repositories from the server filesystem, potentially exposing sensitive code and enabling blind SSRF.
    • Affected Systems: Gogs repository mirror settings in affected builds.
    • Immediate Action: Disable or tightly restrict mirror settings for non-admin users and review existing mirror configurations.
    • Mitigation: Apply the fix that validates mirror addresses the same way migration does, and audit for unexpected local-path mirrors.
  • CVE-2026-52799: Gogs attachment download IDOR
    • Impact: Attackers can download attachments by UUID without proper permission checks, exposing private files from issues, comments, and releases.
    • Affected Systems: Gogs 0.14.1 attachment delivery route /attachments/:uuid, especially where repository viewing is restricted or disabled.
    • Immediate Action: Treat attachment URLs as sensitive, rotate or revoke exposed content if needed, and patch immediately.
    • Mitigation: Enforce repository and parent-object authorization before serving attachments and review logs for unusual attachment access.

Previously Alerted

What to Do Now

  1. Patch Gogs and Budibase immediately on all internet-facing and internal instances.
  2. Disable or limit risky features: notebook previews, organization team management exposure, mirror settings, and automation steps that fetch external URLs.
  3. Review access logs for suspicious GET requests to team actions, unusual attachment downloads, and unexpected repository mirror changes.
  4. Check for account abuse: new org owners, new team members, changed repo settings, unexpected tokens, or unauthorized automation runs.
  5. Rotate secrets if exposure is suspected, especially tokens, webhook credentials, and sensitive files shared through attachments.

Verification: Confirm current versions, compare against vendor guidance, and test whether any exposed routes still accept state-changing GET requests or serve attachments without authorization. Validate that preview pages and automation endpoints are no longer reachable by untrusted users.

Monitoring: Watch for spikes in notebook file views, attachment downloads, org membership changes, mirror sync activity, and outbound requests to unusual domains or metadata IP ranges. Alert on any newly added organization owners or team members outside approved change windows.

Related Resources

  • Internal blog posts: Security team analysis and remediation guidance are recommended for publication; link them here once available.
  • Official vendor advisories: Monitor Gogs and Budibase release notes and security advisories for patch versions and backported fixes.

Keep reading