CISA Warns of Active Exploitation of Gogs Vulnerability Enabling Code Execution
A high-severity security vulnerability affecting Gogs has been actively exploited, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA), which has added it to its Known Exploited Vulnerabilities (KEV) list.
Tracked as CVE-2025-8110 (CVSS score: 8.7), the vulnerability is related to a path traversal scenario in the repository file editor that may lead to code execution.
Gogs Path Traversal Vulnerability: According to a CISA advisory, Gogs has a path traversal vulnerability that affects incorrect Symbolic link processing in the PutContents API and may enable code execution.
Last month, Wiz revealed the vulnerability after claiming to have found it being used in zero-day attacks. By creating a git repository, committing a symbolic link referring to a sensiti...

