8.7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/AU:Y/R:U/V:C
Description
Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
AI Analysis
File overwrite vulnerability in Gogs via the PutContents API, allowing local code execution
Basic Information
ID
CVE-2025-8110
Source
Wiz
Published
Dec 10, 2025 at 13:23
Affected Product
Vendor
Gogs
Product
Gogs
Affected Versions
Gogs Gogs 0
CWE Classification
AI Assessment
AI Score
8.7 / 10
AI Severity
High
Vendor
Gogs
Product
Gogs