cve detail
CVE-2025-8110
naam
Gogs Path Traversal Vulnerability
Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution.
KEV
bekend misbruikt
EPSS
18%
percentiel
95%
vendor
Gogs
product
Gogs
toegevoegd aan KEV
12 jan 2026
due date
02 feb 2026
ransomware
Unknown
CWE
CWE-22
EPSS datum
12 mei 2026
aanbevolen actie
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
notities
https://github.com/gogs/gogs/commit/553707f3fd5f68f47f531cfcff56aa3ec294c6f6 ; https://nvd.nist.gov/vuln/detail/CVE-2025-8110