Vulnerability record · CVE-2025-8110 · published 10 December 2025
CVE-2025-8110: Gogs PutContents API symlink handling allows remote code execution
Gogs · Gogs
The PutContents API in Gogs mishandles symbolic links, letting a user write file content through a symlink and escape the intended repository path (CWE-22 path traversal). Because the write lands outside the repository, an attacker can place executable content that the server later runs, turning a file-write primitive into local code execution. The flaw is remotely reachable over the network and is listed in CISA KEV, so it warrants urgent attention.
Description
Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:
Automated analysis
critical priorityIt is in CISA KEV with a near-term due date, has a very high EPSS score, public exploit references and a patch, and yields remote code execution from a low-privileged account.
What it is
The PutContents API in Gogs mishandles symbolic links, letting a user write file content through a symlink and escape the intended repository path (CWE-22 path traversal). Because the write lands outside the repository, an attacker can place executable content that the server later runs, turning a file-write primitive into local code execution. The flaw is remotely reachable over the network and is listed in CISA KEV, so it warrants urgent attention.
Impact
An attacker with a valid low-privileged account gains code execution in the context of the Gogs server process, which can expose repository data, credentials and the host itself. CVSS 4.0 scores confidentiality, integrity and availability impact as high.
Attack surface
Reached over the network through the PutContents API (CVSS 4.0 vector AV:N/PR:L/UI:N), so a low-privileged authenticated account is required but no user interaction is needed. No pre-authentication path is described in the record.
Exploitation
CISA added it to KEV on 2026-01-12 with a 2026-02-02 remediation due date, and EPSS gives a 30-day probability of 0.82471 (99.6th percentile). A public exploit write-up and a patch pull request are referenced, so exploitation is active and tooling is public.
What to do
- Apply the vendor patch (commit 553707f3fd5f68f47f531cfcff56aa3ec294c6f6 / PR 8078) or upgrade to a fixed Gogs release immediately.
- If patching is not possible, restrict or disable the PutContents API and limit repository write access to trusted accounts.
- Follow CISA KEV required action and BOD 22-01 guidance, including discontinuing use of the product if no mitigation is available.
- Audit Gogs accounts and tokens, remove unused or over-privileged ones, and rotate credentials that may have been exposed.
- Run Gogs with least privilege and isolate it from sensitive hosts and data so code execution does not reach critical systems.
Detection
- Monitor Gogs API logs for PutContents requests, especially writes involving symlinks or paths outside the repository root.
- Alert on new or modified executable files appearing outside expected repository directories on the Gogs host.
- Watch for unexpected child processes spawned by the Gogs server process.
- Review file integrity monitoring and audit logs for symlink creation followed by writes to sensitive paths.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-8110 to the Known Exploited Vulnerabilities catalog on 12 January 2026 as "Gogs Path Traversal Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 2 February 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploit | ExploitThird Party Advisory |
| http://www.openwall.com/lists/oss-security/2025/12/11/3 | Mailing List |
| http://www.openwall.com/lists/oss-security/2025/12/11/4 | Mailing List |
| http://www.openwall.com/lists/oss-security/2026/01/17/4 | Mailing List |
| http://www.openwall.com/lists/oss-security/2026/01/18/1 | Mailing List |
| http://www.openwall.com/lists/oss-security/2026/01/18/2 | Mailing List |
| https://github.com/gogs/gogs/commit/553707f3fd5f68f47f531cfcff56aa3ec294c6f6 | Patch |
| https://github.com/gogs/gogs/pull/8078 | ExploitIssue TrackingPatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-8110 | Third Party AdvisoryUS Government Resource |
Track CVE-2025-8110 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-8110), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.