CVE-2025-8110: Gogs Path Traversal Vulnerability
High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2026-01-12. EPSS: 85.2% chance of exploitation in the next 30 days.
Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
Affected products
- Gogs Gogs: up to and including 0.13.3
Published 2025-12-10. Last modified 2026-06-17.