What it is
Self-hosted Git services sit close to source code, automation tokens, and deployment workflows. A path traversal advisory in Gogs should be treated as a runtime upgrade item when the affected version is part of the deployed service.
How it happens
CVE-2018-20303 is a directory traversal in Gogs's file-upload handling, fixed in Gogs 0.11.82.1218. A crafted upload path lets the file land outside the upload directory on the server.
What an attacker gets
An attacker who can upload files to an affected Gogs server may be able to write files outside the intended directory, on the machine that holds your repositories, deploy keys, and automation tokens.
// what fixvibe reports
What FixVibe reports
Runs when you connect a GitHub repository, on Pro and above. Each finding shows the file and line, its severity and fix steps you can paste into your AI coding tool.
How to fix it
Upgrade Gogs to 0.11.82.1218 or newer, or to a build that includes commit ff93d9dbda5c, regenerate Go module or Dep lock metadata, rebuild the deployed Gogs runtime, and verify the running service reports the patched version before closing the advisory.
