CVE-2025-8110
8.8HIGHImproper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
Publicado: 12/10/2025Atualizado: 1/13/2026
Vulnerabilidade Explorada Conhecida (CISA)
Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution.
Ação Necessária:
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Prazo:
2026-02-02
Descrição
Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
Análise IADesenvolvido por IA
Produtos Afetados
gogsgogs
Referências
- http://wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploitExploitThird Party Advisory
- http://www.openwall.com/lists/oss-security/2025/12/11/3Mailing List
- http://www.openwall.com/lists/oss-security/2025/12/11/4Mailing List
- https://github.com/gogs/gogs/commit/553707f3fd5f68f47f531cfcff56aa3ec294c6f6Patch
- https://github.com/gogs/gogs/pull/8078ExploitIssue TrackingPatchVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-8110Third Party AdvisoryUS Government Resource