FlawAtlas
Search the atlas
CVE-2025-8110 High

Confirmed as exploited

Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs

Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs

Exploit probability 82.7%
Published December 15, 2025
Required by February 2, 2026
Last source change March 3, 2026

01 / ACTION

Required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

61 explicit affected versions

Go gogs.io/gogs
Go gogs.io/gogs

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2026:21483-1

04 / EVIDENCE

Source records

Cybersecurity and Infrastructure Security Agency Known Exploited Vulnerabilities CVE-2025-8110

Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution.

View original source
Open Source Vulnerabilities CVE-2025-8110

Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.

View original source
Open Source Vulnerabilities GHSA-mq8m-42gh-wq7r

Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.

View original source

05 / REFERENCES

Further evidence