The United States Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about the active exploitation of a serious Gogs vulnerability, which been added to the list of Known Exploitable Vulnerabilities (KEV).

The vulnerability, tracked as CVE-2025-8110 and rated CVSS 8.7, is related to a path traversal in the repository file editor that could lead to code execution.
See also: Critical vulnerabilities in InputPlumber allow DoS
“Gogs Path Traversal Vulnerability: Gogs contains a path traversal vulnerability affecting Symbolic link handling in the PutContents API, which could allow code execution,” CISA said in an advisory.
Details of the vulnerability came to light last month when Wiz reported discovering it in zero-day exploits. The vulnerability essentially bypasses protections put in place for another vulnerability, CVE-2024-55947. The goal is to execute code by creating a git repository, committing a symbolic link pointing to a vulnerable target, and using the PutContents API to write data to the symlink.
See also: React Router: Critical vulnerability allows directory traversal attacks

This, in turn, causes the underlying operating system to go to the actual file pointed to by the symlink and replace the target file outside the repository. An attacker could exploit this behavior to replace configuration files Git , specifically the sshCommand setting , giving them code execution privileges.
Wiz reported that it had identified 700 compromised Gogs instances. According to data from the Censys, there are approximately 1,600 Gogs servers exposed online, the majority of which are located in China (991), the U.S. (146), Germany (98), Hong Kong (56), and Russia (49).

Addressing Gogs vulnerability
currently no fixes to address CVE-2025-8110, although pull requests on GitHub indicate that the necessary code changes have been made. “Once the image is built into main, both gogs/gogs:latest and gogs/gogs:next-latest will have this CVE fixed,” one of the project’s maintainers said last week.
See also: Exploiting VMware zero-day vulnerabilities
In the absence of a fix, Gogs users are advised to disable the default open-registration setting and restrict access to the server using a VPN or allow-list. Federal agencies are required to implement the necessary mitigation actions by February 2, 2026.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
