← Vulnerability feed

Vulnerability record · CVE-2025-8110 · published 10 December 2025

CVE-2025-8110: Gogs PutContents API symlink handling allows remote code execution

Gogs · Gogs

The PutContents API in Gogs mishandles symbolic links, letting a user write file content through a symlink and escape the intended repository path (CWE-22 path traversal). Because the write lands outside the repository, an attacker can place executable content that the server later runs, turning a file-write primitive into local code execution. The flaw is remotely reachable over the network and is listed in CISA KEV, so it warrants urgent attention.

8.7 CVSS 4.0 High CISA KEV since 12 Jan 2026 EPSS 85% · top 0.3% CWE-22 · Path traversal
8.7CVSS 4.0 base score
85%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
9References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with a near-term due date, has a very high EPSS score, public exploit references and a patch, and yields remote code execution from a low-privileged account.

What it is

The PutContents API in Gogs mishandles symbolic links, letting a user write file content through a symlink and escape the intended repository path (CWE-22 path traversal). Because the write lands outside the repository, an attacker can place executable content that the server later runs, turning a file-write primitive into local code execution. The flaw is remotely reachable over the network and is listed in CISA KEV, so it warrants urgent attention.

Impact

An attacker with a valid low-privileged account gains code execution in the context of the Gogs server process, which can expose repository data, credentials and the host itself. CVSS 4.0 scores confidentiality, integrity and availability impact as high.

Attack surface

Reached over the network through the PutContents API (CVSS 4.0 vector AV:N/PR:L/UI:N), so a low-privileged authenticated account is required but no user interaction is needed. No pre-authentication path is described in the record.

Exploitation

CISA added it to KEV on 2026-01-12 with a 2026-02-02 remediation due date, and EPSS gives a 30-day probability of 0.82471 (99.6th percentile). A public exploit write-up and a patch pull request are referenced, so exploitation is active and tooling is public.

What to do

  • Apply the vendor patch (commit 553707f3fd5f68f47f531cfcff56aa3ec294c6f6 / PR 8078) or upgrade to a fixed Gogs release immediately.
  • If patching is not possible, restrict or disable the PutContents API and limit repository write access to trusted accounts.
  • Follow CISA KEV required action and BOD 22-01 guidance, including discontinuing use of the product if no mitigation is available.
  • Audit Gogs accounts and tokens, remove unused or over-privileged ones, and rotate credentials that may have been exposed.
  • Run Gogs with least privilege and isolate it from sensitive hosts and data so code execution does not reach critical systems.

Detection

  • Monitor Gogs API logs for PutContents requests, especially writes involving symlinks or paths outside the repository root.
  • Alert on new or modified executable files appearing outside expected repository directories on the Gogs host.
  • Watch for unexpected child processes spawned by the Gogs server process.
  • Review file integrity monitoring and audit logs for symlink creation followed by writes to sensitive paths.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-8110 to the Known Exploited Vulnerabilities catalog on 12 January 2026 as "Gogs Path Traversal Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 2 February 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-8110 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2024-39930Gogs argument injection vulnerabilityThe built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated atta…EPSS 7.7%9.9CVE-2024-39931Gogs internal file deletion via path handling flawGogs through 0.13.0 allows deletion of internal files. The flaw is a path handling issue (CWE-552) that lets a user with a valid account remove files…EPSS 53%analysed9.9CVE-2024-39932Gogs code injection vulnerabilityGogs through 0.13.0 allows argument injection during the previewing of changes.EPSS 17%9.8CVE-2024-56731Gogs vulnerabilityGogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the .git directory and achieve rem…EPSS 1.2%9.8CVE-2022-1884Gogs os command injection vulnerabilityA remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to imp…EPSS 1.8%9.8CVE-2022-2024Gogs OS command injection before 0.12.11Gogs, a self-hosted Git service, contains an OS command injection flaw (CWE-78) in versions prior to 0.12.11. The CVSS 3.1 vector rates it 9.8 critic…EPSS 98%analysed9.8CVE-2022-1986Gogs os command injection vulnerabilityOS Command Injection in GitHub repository gogs/gogs prior to 0.12.9.EPSS 4.5%9.8CVE-2019-14544Gogs missing authorization vulnerabilityroutes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks.EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2025-8110), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.