CVE 8.7 HIGH

File overwrite in file update API in Gogs_CVE-2025-8110

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/AU:Y/R:U/V:C

Description

Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.

AI Analysis

File overwrite vulnerability in Gogs via the PutContents API, allowing local code execution

Basic Information

ID CVE-2025-8110
Source Wiz
Published Dec 10, 2025 at 13:23

Affected Product

Vendor Gogs
Product Gogs
Affected Versions Gogs Gogs 0

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor Gogs
Product Gogs

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.