CVE-2025-8110: Gogs Path Traversal Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2026-01-12. EPSS: 85.2% chance of exploitation in the next 30 days.

Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.

Affected products

  • Gogs Gogs: up to and including 0.13.3

Published 2025-12-10. Last modified 2026-06-17.