CVE-2025-8110
File overwrite in file update API in Gogs
- Published
- Dec 10, 2025
- Updated
- Feb 26, 2026
- Assigning CNA
- Wiz
- Evidence observed
- Jan 12, 2026
Primary CVSS
nvd · CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:X/U:XHigh · next 30 days
- Percentile
- 99.7%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
Sources
21- CVE-2025-8110Exploit
RCE exploit for Gogs <= 0.13.3
- CVE-2025-8110Exploit
CVE-2025-8110 — Gogs <= 0.13.3 Arbitrary File Write via Symlink Traversal in PutContents API
Gogs CVE-2025-8110 RCE Exploit
- CVE-2025-8110Exploit
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.