High severity8.8CISA KEVNVD Advisory· Published Dec 10, 2025· Updated Jun 17, 2026
CVE-2025-8110
CVE-2025-8110
Description
Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
gogs.io/gogsGo | <= 0.13.3 | — |
Affected products
5- ghsa-coords3 versionspkg:golang/gogs.io/gogspkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0
<= 0.13.3+ 2 more
- (no CPE)range: <= 0.13.3
- (no CPE)range: < 0.0.20251230T014957-150000.1.134.1
- (no CPE)range: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
12- github.com/gogs/gogs/commit/553707f3fd5f68f47f531cfcff56aa3ec294c6f6nvdPatchWEB
- wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploitnvdExploitThird Party AdvisoryWEB
- github.com/gogs/gogs/pull/8078nvdExploitIssue TrackingPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-mq8m-42gh-wq7rghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-8110ghsaADVISORY
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdThird Party AdvisoryUS Government ResourceWEB
- www.openwall.com/lists/oss-security/2025/12/11/3nvdMailing ListWEB
- www.openwall.com/lists/oss-security/2025/12/11/4nvdMailing ListWEB
- www.openwall.com/lists/oss-security/2026/01/17/4nvdMailing ListWEB
- www.openwall.com/lists/oss-security/2026/01/18/1nvdMailing ListWEB
- www.openwall.com/lists/oss-security/2026/01/18/2nvdMailing ListWEB
- github.com/gogs/gogs/pull/8082ghsaWEB
News mentions
3- Gogs patches critical zero-day enabling remote code executionBleepingComputer · Jun 8, 2026
- Gogs Zero-Day Exposes Servers to Remote Code ExecutionSecurityWeek · May 29, 2026
- New Gogs zero-day flaw lets hackers get remote code executionBleepingComputer · May 28, 2026