8.7
HIGH CVSS 4.0
CVE-2025-8110
File overwrite in file update API in Gogs
Description

Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.

INFO

Published Date :

Dec. 10, 2025, 2:16 p.m.

Last Modified :

Dec. 12, 2025, 3:18 p.m.

Remotely Exploit :

Yes !

Source :

9947ef80-c5d5-474a-bbab-97341a59000e
Affected Products

The following products are affected by CVE-2025-8110 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Gogs gogs
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 4.0 HIGH 9947ef80-c5d5-474a-bbab-97341a59000e
CVSS 4.0 HIGH 9947ef80-c5d5-474a-bbab-97341a59000e
Solution
Address improper symbolic link handling in the PutContents API to prevent local code execution.
  • Update Gogs to the latest version.
  • Review and sanitize all symbolic link operations.
  • Implement strict input validation for API calls.
Public PoC/Exploit Available at Github

CVE-2025-8110 has a 3 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2025-8110.

URL Resource
http://wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploit
http://www.openwall.com/lists/oss-security/2025/12/11/3
http://www.openwall.com/lists/oss-security/2025/12/11/4
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2025-8110 is associated with the following CWEs:

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

CVE-2025-8110 PoC

Python

Updated: 1 day, 6 hours ago
2 stars 0 fork 0 watcher
Born at : Dec. 13, 2025, 4:15 a.m. This repo has been linked 1 different CVEs too.

CVE-2025-8110

Python

Updated: 1 week, 1 day ago
2 stars 0 fork 0 watcher
Born at : Dec. 11, 2025, 7:10 p.m. This repo has been linked 1 different CVEs too.

Detection template for CVE-2025-8110

Updated: 5 days, 5 hours ago
21 stars 0 fork 0 watcher
Born at : Dec. 11, 2025, 10:37 a.m. This repo has been linked 1 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2025-8110 vulnerability anywhere in the article.

  • Daily CyberSecurity
The Developer Win: GitHub Postpones Self-Hosted Runner Fee After Massive Community Outcry

Recently, the code hosting platform GitHub published a blog post announcing that, starting March 1, 2026, GitHub Actions would begin charging an additional platform fee. Under the proposed change, dev ... Read more

Published Date: Dec 18, 2025 (4 days, 2 hours ago)
  • Daily CyberSecurity
CVE-2025-37164 (CVSS 10.0): Unauthenticated HPE OneView RCE Grants Total Control Over Data Centers

Hewlett Packard Enterprise (HPE) has sounded the alarm on a catastrophic security vulnerability in its flagship infrastructure management software, OneView. The flaw, tracked as CVE-2025-37164, has be ... Read more

Published Date: Dec 18, 2025 (4 days, 2 hours ago)
  • Daily CyberSecurity
CISA Alert: Chinese Hackers Weaponize CVSS 10 Cisco Zero-Day & SonicWall Exploit Chains

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive adding three critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, signaling that ha ... Read more

Published Date: Dec 18, 2025 (4 days, 2 hours ago)
  • Daily CyberSecurity
Cisco Zero-Day Siege: Chinese Group UAT-9686 Deploys ‘Aqua’ Malware via CVSS 10 Root Exploit

A critical zero-day vulnerability in Cisco’s secure email appliances is under active siege by a sophisticated Chinese hacking group, granting them total control over sensitive network gateways. The ca ... Read more

Published Date: Dec 18, 2025 (4 days, 3 hours ago)
  • Daily CyberSecurity
Academic Ambush: How the Forum Troll APT Hijacks Scholars’ Systems via Fake Plagiarism Reports

A relentless Advanced Persistent Threat (APT) group known as “Forum Troll” has shifted its crosshairs from corporate networks to the academic elite, launching a precision phishing campaign against Rus ... Read more

Published Date: Dec 18, 2025 (4 days, 4 hours ago)
  • Daily CyberSecurity
Locked Out of the Cloud: Hackers Use AWS Termination Protection to Hijack ECS for Unstoppable Crypto Mining

In a striking display of cloud-native tradecraft, cybercriminals have been caught turning legitimate AWS environments into illicit cryptocurrency mining farms, utilizing a “novel persistence technique ... Read more

Published Date: Dec 18, 2025 (4 days, 4 hours ago)
  • Daily CyberSecurity
Blurred Deception: Russian APT Targets Transnistria and NATO with High-Pressure Phishing Lures

A sophisticated Russian Advanced Persistent Threat (APT) group has launched a targeted credential harvesting campaign against the governing body of Transnistria (the Pridnestrovian Moldavian Republic) ... Read more

Published Date: Dec 18, 2025 (4 days, 4 hours ago)
  • Daily CyberSecurity
“Better Auth” Framework Alert: The Double-Slash Trick That Bypasses Security Controls

A high-severity vulnerability has been disclosed in Better Auth, a rapidly growing authentication framework for TypeScript, potentially allowing attackers to bypass critical access controls with a sim ... Read more

Published Date: Dec 18, 2025 (4 days, 5 hours ago)
  • Daily CyberSecurity
Ink Dragon’s Global Mesh: How Chinese Spies Turn Compromised Government Servers into C2 Relay Nodes

A sophisticated Chinese cyber-espionage group is rewriting the rules of persistence, turning compromised government servers into a living, breathing command network. A new report from Check Point Rese ... Read more

Published Date: Dec 18, 2025 (4 days, 5 hours ago)
  • Daily CyberSecurity
CVE-2025-46295 (CVSS 9.8): Critical Apache Commons Text Flaw Risks Total Server Takeover

A critical vulnerability has been fixed in Apache Commons Text, a ubiquitous Java library used for text manipulation, preventing what could have been a widespread remote code execution (RCE) crisis. T ... Read more

Published Date: Dec 18, 2025 (4 days, 5 hours ago)
  • Daily CyberSecurity
Node.js Alert: systeminformation Flaw Risks Windows RCE for 16M+ Monthly Users

A high-severity vulnerability has been uncovered in systeminformation, a massively popular Node.js library used by millions of developers to retrieve system metrics. Tracked as CVE-2025-68154, the fla ... Read more

Published Date: Dec 18, 2025 (4 days, 5 hours ago)
  • Daily CyberSecurity
Self-Hosting No Longer Free: GitHub Introduces New $0.002/Min Platform Fee for Actions

Microsoft-owned code hosting platform GitHub has announced a new pricing change for its Actions service. Previously, GitHub Actions offered a free control plane: as long as workflows ran on servers no ... Read more

Published Date: Dec 18, 2025 (4 days, 5 hours ago)
  • Daily CyberSecurity
Prompt to Play: YouTube’s New Gemini 3 Tool Lets Creators Speak Games Into Existence

Google’s fixation on embedding AI across all of its services appears boundless. Following earlier experiments with the “Playables” mini-game feature on YouTube, YouTube Gaming has now announced an ope ... Read more

Published Date: Dec 17, 2025 (4 days, 21 hours ago)
  • Daily CyberSecurity
Hardware Inflation: Dell Hikes Business PC Prices by up to 30% as Memory Costs Skyrocket

Dell recently circulated an internal memo to employees disclosing that, due to rising costs for memory and storage hardware, prices for its business-oriented products will increase starting December 1 ... Read more

Published Date: Dec 17, 2025 (4 days, 21 hours ago)
  • Daily CyberSecurity
“Too Many Pointless Things”: Torvalds Rejects TSEM Module, Sparking a Linux Security Civil War

A fresh dispute has flared up within the Linux kernel developer community over security modules. The trigger was an appeal from one contributor who revisited a proposal made three years ago for a modu ... Read more

Published Date: Dec 17, 2025 (5 days ago)
  • Daily CyberSecurity
NVIDIA Critical AI Patch: Isaac Lab and NeMo Framework Flaws Risk Full Code Execution

NVIDIA has rolled out a sweeping security update addressing multiple high-severity vulnerabilities across its AI and simulation ecosystem. The patches cover the NeMo Framework, Resiliency Extension, a ... Read more

Published Date: Dec 17, 2025 (5 days, 2 hours ago)
  • Daily CyberSecurity
Google Chrome Emergency Update: High-Severity Memory Corruption Flaws Fixed in WebGPU and V8

Google has rolled out an important security update for the Stable desktop channel, patching two high-severity vulnerabilities that expose users to potential memory corruption attacks. The release brin ... Read more

Published Date: Dec 17, 2025 (5 days, 3 hours ago)
  • Daily CyberSecurity
Critical FreePBX Flaw (CVE-2025-66039) Risks PBX Takeover via Authentication Bypass in ‘webserver’ Auth Mode

A critical security vulnerability has been discovered in FreePBX, the world’s most popular open-source PBX platform, potentially leaving thousands of phone systems vulnerable to complete takeover. Tra ... Read more

Published Date: Dec 17, 2025 (5 days, 4 hours ago)
  • Daily CyberSecurity
Windows Admin Center Flaw (CVE-2025-64669): How a Simple Folder Permission Opened the Door to SYSTEM Access

A high-severity security oversight in Microsoft’s Windows Admin Center (WAC) has been unearthed, revealing how a basic permission error could allow any standard user to seize complete control of a ser ... Read more

Published Date: Dec 17, 2025 (5 days, 5 hours ago)
  • Daily CyberSecurity
GhostPairing: New Attack Hijacks WhatsApp via Linked Devices, Tricking Users with Fake Facebook QR Code

A deceptive new cyberattack campaign is turning one of WhatsApp’s most convenient features into a weapon, allowing hackers to take full control of user accounts without ever stealing a password or tou ... Read more

Published Date: Dec 17, 2025 (5 days, 5 hours ago)

The following table lists the changes that have been made to the CVE-2025-8110 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by af854a3a-2127-422b-91ae-364da2661108

    Dec. 11, 2025

    Action Type Old Value New Value
    Added Reference http://www.openwall.com/lists/oss-security/2025/12/11/4
  • CVE Modified by af854a3a-2127-422b-91ae-364da2661108

    Dec. 11, 2025

    Action Type Old Value New Value
    Added Reference http://www.openwall.com/lists/oss-security/2025/12/11/3
  • New CVE Received by 9947ef80-c5d5-474a-bbab-97341a59000e

    Dec. 10, 2025

    Action Type Old Value New Value
    Added Description Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
    Added CVSS V4.0 AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:X/U:X
    Added CWE CWE-22
    Added Reference http://wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploit
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
Vulnerability Scoring Details
Base CVSS Score: 8.7
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability