Researcher reported the vuln in March. Maintainers haven't responded to his messages since

Two months after Rapid7 discovered the hole in the Git service, the project maintainer has yet to patch the bug.

An unpatched zero-day vulnerability in the Gogs self-hosted Git service can allow attackers to gain remote code execution (RCE) on Internet-facing instances.