Confirmed as exploited
Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs
Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs
01 / ACTION
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
02 / AFFECTED SOFTWARE
Affected packages
61 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution.
Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs
Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
05 / REFERENCES
Further evidence
- http://wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploit
- http://www.openwall.com/lists/oss-security/2025/12/11/3
- http://www.openwall.com/lists/oss-security/2025/12/11/4
- http://www.openwall.com/lists/oss-security/2026/01/17/4
- http://www.openwall.com/lists/oss-security/2026/01/18/1
- http://www.openwall.com/lists/oss-security/2026/01/18/2
- https://github.com/gogs/gogs/commit/553707f3fd5f68f47f531cfcff56aa3ec294c6f6
- https://github.com/gogs/gogs/pull/8078
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-8110
- https://github.com/advisories/GHSA-mq8m-42gh-wq7r
- https://nvd.nist.gov/vuln/detail/CVE-2025-8110
- https://github.com/gogs/gogs
- https://github.com/gogs/gogs/pull/8082