8.8

CVE-2025-8110

Warnung
Medienbericht
Exploit

File overwrite in file update API in Gogs

Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GogsGogs Version <= 0.13.3
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login

12.01.2026: CISA Known Exploited Vulnerabilities (KEV) Catalog

Gogs Path Traversal Vulnerability

Schwachstelle

Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution.

Beschreibung

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 76.54% 0.995
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
9947ef80-c5d5-474a-bbab-97341a59000e 8.7 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:X/U:X
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.06.2026 18:41
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
05.06.2026 12:46
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
13.01.2026 11:40
http://wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploit
Third Party Advisory
Exploit
http://www.openwall.com/lists/oss-security/2025/12/11/3
Mailing List
http://www.openwall.com/lists/oss-security/2025/12/11/4
Mailing List
https://github.com/gogs/gogs/pull/8078
Patch
Vendor Advisory
Exploit
Issue Tracking
https://github.com/gogs/gogs/commit/553707f3fd5f68f47f531cfcff56aa3ec294c6f6
Patch
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-8110
Third Party Advisory
US Government Resource
http://www.openwall.com/lists/oss-security/2026/01/17/4
Mailing List
http://www.openwall.com/lists/oss-security/2026/01/18/1
Mailing List
http://www.openwall.com/lists/oss-security/2026/01/18/2
Mailing List