ID:12272 - Exploit for Path traversal in gogs - CVE-2025-8110

 
Main Vulnerability Database Exploits ID:12272 - Exploit for Path traversal in gogs - CVE-2025-8110

ID:12272 - Exploit for Path traversal in gogs - CVE-2025-8110

Published: January 9, 2026


Vulnerability identifier: #VU119869
Vulnerability risk: High
CVE-ID: CVE-2025-8110
CWE-ID: CWE-22
Exploitation vector: Remote access
Vulnerable software:
gogs

Link to public exploit:


Vulnerability description

The vulnerability allows a remote user to perform directory traversal attacks.

The vulnerability exists due to improper symbolic link handling in the PutContents API caused by insufficient patch for #VU119868 (CVE-2024-55947). A remote user can write file to arbitrary location on the system and execute arbitrary code. 

Note, the vulnerability is being actively exploited in the wild.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.