CVE-2025-8110
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 5, 2026
4 articles
Published: 2025-12-10
EPSS Score
Source: FIRST.org · 2026-05-24
17.74%
probability
This CVE has a 17.74% probability
of being exploited in the next 30 days.
0%
Top 95.2th percentile of all CVEs
100%
CVSS v4.0 NEW
Source: VulnerabilityLookup (CIRCL)8.7
HIGH
Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
Low
User Interaction
None
Vulnerable System Confidentiality Impact
High
Vulnerable System Integrity Impact
High
Vulnerable System Availability Impact
High
Subsequent System Confidentiality Impact
None
Subsequent System Integrity Impact
None
Subsequent System Availability Impact
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/AU:Y/R:U/V:C
Description
VulnerabilityLookup (CNA)Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
Affected Products
Gogs
Gogs
0
Attack Intelligence
Exploits & PoC
zAbuQasem/gogs-CVE-2025-8110
CVE-2025-8110 PoC
21
TYehan/CVE-2025-8110-Gogs-RCE-Exploit
Gogs CVE-2025-8110 RCE Exploit
2
3jee/CVE-2025-8110
CVE-2025-8110 — Gogs <= 0.13.3 Arbitrary File Write via Symlink Traversal in PutContents API
2
Ghxstsec/CVE-2025-8110
PoC CVE-2025-8110 — Ghxstsec/CVE-2025-8110
2
kayl22/cve-2025-8110-GOGS-RCE
GOGS RCE cve-2025-8110 python script that automates the whole attack chain of creating a repository with a symlink file pointing to .git/config and th
2
0dgt/CVE-2025-8110
RCE exploit for Gogs <= 0.13.3
1
George0Papasotiriou/CVE-2025-8110-Gogs-Remote-Code-Execution
PoC CVE-2025-8110 — George0Papasotiriou/CVE-2025-8110-Gogs-Remote-Code-Execution
1
111ddea/goga-cve-2025-8110
验证 Gogs 版本 0.13.2 是否存在 **CVE-2025-8110 (符号链接文件覆盖)** 漏洞。
0
8 repos — triés par ⭐
Rechercher sur GitHub ↗
Signal Intelligence
Confidence
95%
EPSS
17.74%
CVSS v4.0
8.7
Mentions
4
Last Seen
Jan 13, 2026
CNA Information
CNA Assigner
Wiz
CNA Title
File overwrite in file update API in Gogs
Analyst Note
CVE-2025-8110 meets all zero-day criteria: explicitly described as 'zero-day' and 'unpatched' in multiple authoritative sources (BleepingComputer, TheHackerNews), active exploitation documented across 700+ instances, CISA warning issued and KEV listing confirmed, and exploitation occurred before patch availability (published 2025-12-10 with no prior patch date indicated).
Threat Actors 8
APT 41
apt_group
Information theft and espionage
🇨🇳 CN
APT 28
apt_group
Information theft and espionage
🇷🇺 RU
Hacking Team
apt_group
🇮🇹 IT
Gamaredon Group
apt_group
Information theft and espionage
🇷🇺 RU
TAG-28
apt_group
Information theft and espionage
🇨🇳 CN
RedGolf
apt_group
Information theft and espionage
🇨🇳 CN
Roaming Tiger
apt_group
Information theft and espionage
🇨🇳 CN
White Bear
apt_group
Information theft and espionage
🇷🇺 RU
Triage Info
Decided atMar 05, 2026
Published DateDec 10, 2025