Multiple outlets report a critical vulnerability in Gogs, a self-hosted Git service, that can lead to remote code execution (RCE). The flaw is described as having a CVSS score of 9.4 and is characterized as an argument injection issue. According to the reporting, exploitation requires authentication, and attackers can trigger code execution by submitting or leveraging pull requests that contain malicious branch names under certain conditions. The vulnerability is described as affecting Internet-facing instances that have not been patched, and it allows malicious input to be processed in a way that results in RCE. One outlet notes that a CVE identifier is not referenced in its source material, while another emphasizes the zero-day nature of the issue and highlights the mechanism involving pull requests and branch-name manipulation. The reports collectively indicate that the risk is tied to how Gogs handles branch names and pull request-related data when processing requests from authenticated users.