HIGH
CVE-2025-8110
CVSS
8.8
KEV
Description
Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
Summary dbcve.org
Improper symbolic link handling in the PutContents API of Gogs allows an attacker to write files to arbitrary locations on the host system through malicious symlinks, leading to local code execution.
Mitigation
Fix the PutContents API to properly validate and resolve symbolic links before file operations, ensuring symlinks cannot be used to traverse outside the intended repository directory.
Weakness (CWE)
CWE-22
Path Traversal
EPSS Score
82.47%
Probability of exploitation in next 30 days
99.6th percentile
References
http://wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploit
Exploit, Third Party Advisory
http://www.openwall.com/lists/oss-security/2025/12/11/3
Mailing List
http://www.openwall.com/lists/oss-security/2025/12/11/4
Mailing List
http://www.openwall.com/lists/oss-security/2026/01/17/4
Mailing List
http://www.openwall.com/lists/oss-security/2026/01/18/1
Mailing List
http://www.openwall.com/lists/oss-security/2026/01/18/2
Mailing List
https://github.com/gogs/gogs/commit/553707f3fd5f68f47f531cfcff56aa3ec294c6f6
Patch
https://github.com/gogs/gogs/pull/8078
Exploit, Issue Tracking, Patch, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-8110
Third Party Advisory, US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.