CVE-2025-8110
HIGHCVSS 8.8/10Actively ExploitedEPSS 76.54%
Last modified
CVE-2025-8110 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.. CISA has confirmed active exploitation in the wild. EPSS estimates a 76.54% chance of exploitation in the next 30 days.
Description
Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gogs | Gogs | <= 0.13.3 |
References
- https://wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploitExploit, Third Party Advisory
- https://github.com/gogs/gogs/pull/8078Exploit, Issue Tracking, Patch, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-8110Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-8110?
Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
How severe is CVE-2025-8110?
CVE-2025-8110 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 76.54% probability of exploitation in the next 30 days. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.
How do I fix CVE-2025-8110?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-8104The Memory Usage plugin for WordPress is vulnerable to Cross…4.3
- CVE-2025-8105The The Soledad theme for WordPress is vulnerable to arbitra…7.3
- CVE-2025-8106Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-8107In OceanBase's Oracle tenant mode, a malicious user with spe…6.3
- CVE-2025-8108An ACAP configuration file has improper permissions and lack…6.7
- CVE-2025-8109Software installed and run as a non-privileged user may cond…8.8
- CVE-2025-8113The Ebook Store WordPress plugin before 5.8015 does not esca…6.1
- CVE-2025-8114A flaw was found in libssh, a library that implements the SS…4.7
- CVE-2025-8115A vulnerability has been found in PHPGurukul Taxi Stand Mana…5.4
- CVE-2025-8116PAD CMS is vulnerable to Reflected XSS in printing and save …6.1
- CVE-2025-8117PAD CMS improperly initializes parameter used for password r…7.5
- CVE-2025-8118PAD CMS implements weak client-side brute-force protection b…6.5
Are you affected by CVE-2025-8110?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
