CVE-2025-8110CISA KEV: Actively Exploited

Gogs Path Traversal Vulnerability

Published Jan 12, 2026·Updated Jan 12, 2026

Description

Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution.

Public Exploits & PoCs17 found

[POC] GHSA-3mgp-fx93-9xv5 — CVE-2025-8110

PoC exploit for CVE-2025-8110

4

PoC: gogs-CVE-2025-8110

CVE-2025-8110 PoC

2

PoC: CVE-2025-8110

RCE exploit for Gogs <= 0.13.3

1

PoC: CVE-2025-8110-Gogs-RCE-Exploit

Gogs CVE-2025-8110 RCE Exploit

1

PoC: CVE-2025-8110

Detection template for CVE-2025-8110

1

PoC: CVE-2025-8110-PoC

CVE-2025-8110 Proof of Concept

PoC: coreweave-demo-2026-05

Verified vulnerability journey for CVE-2025-8110 (Gogs) and CVE-2025-3248 (Langflow) — risk triage, exploitability verification, verified patches.

PoC: CVE-2025-8110-Gogs-RCE-Exploit

Gogs CVE-2025-8110 RCE Exploit

PoC: CVE-2025-8110-Silentium-HTB

CVE-2025-8110 Specifically for the Silentium box on HTB.

PoC: CVE-2025-8110

Gogs RCE PoC - CVE-2025-8110

PoC: CVE-2025-8110

Gogs Symlink Traversal → RCE

PoC: CVE-2025-8110-Authenticated-Remote-Code-Execution-on-Gogs-v0.13.3-

A remote code execution to get a reverse shell on Gogs (v0.13.3)

PoC: cve-2025-8110-GOGS-RCE

GOGS RCE cve-2025-8110 python script that automates the whole attack chain of creating a repository with a symlink file pointing to .git/config and then triggering rce via a poisoned sshCommand on the config file.

PoC: CVE-2025-8110

CVE-2025-8110 — Gogs <= 0.13.3 Arbitrary File Write via Symlink Traversal in PutContents API

PoC: CVE-2025-8110

🔍 Detect improper symbolic link handling in Gogs' PutContents API, exposing local code execution risks for versions 0.13.3 and earlier.

PoC: goga-cve-2025-8110

验证 Gogs 版本 0.13.2 是否存在 **CVE-2025-8110 (符号链接文件覆盖)** 漏洞。

PoC: Blackash-CVE-2025-8110

CVE-2025-8110

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free