Gogs's write-level collaborators can mutate admin-only repository settings via API (CVE-2026-52808) | HOL Guard CVE