CVE-2025-8110

HIGH KEV NUCLEI LAB

Gogs < 0.13.3 - Path Traversal

Title source: rule

Description

Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.

Exploits (18)

nomisec SCANNER 22 stars
by rxerium · poc
https://github.com/rxerium/CVE-2025-8110
github WORKING POC 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2025/CVE-2025-8110
nomisec WORKING POC 6 stars
by zAbuQasem · remote-auth
https://github.com/zAbuQasem/gogs-CVE-2025-8110
nomisec WORKING POC 1 stars
by George0Papasotiriou · poc
https://github.com/George0Papasotiriou/CVE-2025-8110-Gogs-Remote-Code-Execution
nomisec WORKING POC
by hassan-hamadi · remote
https://github.com/hassan-hamadi/CVE-2025-8110-Silentium-HTB
nomisec WORKING POC
by X4BROZER · remote-auth
https://github.com/X4BROZER/CVE-2025-8110
nomisec WORKING POC
by NetsecBandit · remote-auth
https://github.com/NetsecBandit/CVE-2025-8110-Exploit
nomisec WORKING POC
by popyue · remote
https://github.com/popyue/CVE-2025-8110
nomisec WORKING POC
by 0dgt · poc
https://github.com/0dgt/CVE-2025-8110
nomisec WORKING POC
by TYehan · remote
https://github.com/TYehan/CVE-2025-8110-Gogs-RCE-Exploit
nomisec WORKING POC
by manbahadurthapa1248 · poc
https://github.com/manbahadurthapa1248/CVE-2025-8110-Authenticated-Remote-Code-Execution-on-Gogs-v0.13.3-
nomisec WORKING POC
by kayl22 · poc
https://github.com/kayl22/cve-2025-8110-GOGS-RCE
nomisec WORKING POC
by Ghxstsec · poc
https://github.com/Ghxstsec/CVE-2025-8110
nomisec WORKING POC
by 3jee · poc
https://github.com/3jee/CVE-2025-8110
nomisec SCANNER
by freiwi · poc
https://github.com/freiwi/CVE-2025-8110
nomisec WORKING POC
by 111ddea · remote-auth
https://github.com/111ddea/goga-cve-2025-8110

Nuclei Templates (1)

Gogs <= 0.13.3 - Remote Code Execution
HIGHVERIFIEDby rxerium
Shodan: http.title:"Sign In - Gogs"

Scores

CVSS v3 8.8
EPSS 0.2140
EPSS Percentile 95.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Lab Environment

COMMUNITY
Community Lab
docker pull gogs/gogs:latest@sha256:89e582254071d6f63636fd5f83e24ee09921e62193456c107fd2d6615786c621
+13 more repos

Details

CISA KEV 2026-01-12
VulnCheck KEV 2025-12-10
ENISA EUVD EUVD-2025-202425
CWE
CWE-22
Status published
Products (2)
gogs/gogs < 0.13.3
gogs.io/gogs 0Go
Published Dec 10, 2025
KEV Added Jan 12, 2026
Tracked Since Feb 18, 2026