Feed/CVE-2025-8110
CVE-2025-8110CISA KEV: Actively Exploited

Gogs Path Traversal Vulnerability

Published Jan 12, 2026·Updated Jan 12, 2026

NVD Description

Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution.

Public Exploits & PoCs21 found

[POC] GHSA-3mgp-fx93-9xv5 — CVE-2025-8110

PoC exploit for CVE-2025-8110

4

[POC] GHSA-8qqm-fp2q-v734 — CVE-2025-8110-gogs-poc

PoC for CVE-2025-8110 - Gogs arbitrary file write via symlink

3

PoC: gogs-CVE-2025-8110

CVE-2025-8110 PoC

2

PoC: CVE-2025-8110

RCE exploit for Gogs <= 0.13.3

1

PoC: CVE-2025-8110-Gogs-RCE-Exploit

Gogs CVE-2025-8110 RCE Exploit

1

PoC: CVE-2025-8110

Detection template for CVE-2025-8110

1

PoC: CVE-2025-8110

PoC for CVE-2025-8110: Authenticated RCE in Gogs via symlink bypass in PutContents API

PoC: CVE-2025-8110

Gogs service Exploit and get the root user

PoC: ghostlink-writeup

Ghostlink HTB — Full Chain AD + Gogs Exploitation | MQTT → NTLM Relay → Path Traversal → CVE-2025-8110 → ADCS ESC11 → DCSync | AMN SECURITY

PoC: CVE-2025-8110-PoC

CVE-2025-8110 Proof of Concept

PoC: coreweave-demo-2026-05

Verified vulnerability journey for CVE-2025-8110 (Gogs) and CVE-2025-3248 (Langflow) — risk triage, exploitability verification, verified patches.

PoC: CVE-2025-8110-Gogs-RCE-Exploit

Gogs CVE-2025-8110 RCE Exploit

PoC: CVE-2025-8110-Silentium-HTB

CVE-2025-8110 Specifically for the Silentium box on HTB.

PoC: CVE-2025-8110

Gogs RCE PoC - CVE-2025-8110

PoC: CVE-2025-8110

Gogs Symlink Traversal → RCE

PoC: CVE-2025-8110-Authenticated-Remote-Code-Execution-on-Gogs-v0.13.3-

A remote code execution to get a reverse shell on Gogs (v0.13.3)

PoC: cve-2025-8110-GOGS-RCE

GOGS RCE cve-2025-8110 python script that automates the whole attack chain of creating a repository with a symlink file pointing to .git/config and then triggering rce via a poisoned sshCommand on the config file.

PoC: CVE-2025-8110

CVE-2025-8110 — Gogs <= 0.13.3 Arbitrary File Write via Symlink Traversal in PutContents API

PoC: CVE-2025-8110

🔍 Detect improper symbolic link handling in Gogs' PutContents API, exposing local code execution risks for versions 0.13.3 and earlier.

PoC: goga-cve-2025-8110

验证 Gogs 版本 0.13.2 是否存在 **CVE-2025-8110 (符号链接文件覆盖)** 漏洞。

PoC: Blackash-CVE-2025-8110

CVE-2025-8110

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free