CVE-2025-8110
Gogs vulnerable to a bypass of CVE-2024-55947
What Should I Do?
Patch Immediately
This vulnerability is confirmed under active exploitation (CISA KEV). Patch within 24-48 hours if possible.
Summary
Affected Packages (1)
| Package | Ecosystem | Affected | Fixed In |
|---|---|---|---|
| gogs.io/gogs | go | All versions | Range-based data available |
Vulnerability Classification
Common Weakness Enumeration (CWE) identifiers for this vulnerability type.
- CWE-22Path TraversalMITRE
CVSS Score Breakdown
What the CVSS (Common Vulnerability Scoring System) 8.8 score means for each attack dimension.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-8110ADVISORY
- https://github.com/gogs/gogs/pull/8078WEB
- https://github.com/gogs/gogs/pull/8082WEB
- https://github.com/gogs/gogs/commit/553707f3fd5f68f47f531cfcff56aa3ec294c6f6WEB
- https://github.com/advisories/GHSA-mq8m-42gh-wq7rADVISORY
- https://github.com/gogs/gogsPACKAGE
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-8110WEB
- https://wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploitWEB
- https://www.openwall.com/lists/oss-security/2025/12/11/3WEB
- https://www.openwall.com/lists/oss-security/2025/12/11/4WEB
- https://www.openwall.com/lists/oss-security/2026/01/17/4WEB
- https://www.openwall.com/lists/oss-security/2026/01/18/1WEB
- https://www.openwall.com/lists/oss-security/2026/01/18/2WEB
Frequently Asked Questions
- What is CVE-2025-8110?
- Gogs vulnerable to a bypass of CVE-2024-55947 This vulnerability has been assigned a severity rating of HIGH (CVSS score: 8.8/10).
- How do I check if my project is affected by CVE-2025-8110?
- CVE-2025-8110 affects gogs.io/gogs. This vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, meaning it is being actively exploited in the wild. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2025-8110 and 200,000+ other known vulnerabilities.
Severity & Exploitability
High exploitability or significant impact. Prioritize remediation within days.
This vulnerability is in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild.
Remediation deadline: February 2, 2026
Also Known As
Related CVEs
- CVE-2022-1986CRITICAL
OS Command Injection in file editor in Gogs
- CVE-2026-52811CRITICAL
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym
- CVE-2024-39932CRITICAL
Gogs allows argument injection during the previewing of changes
- CVE-2026-52813CRITICAL
Gogs has Path Traversal in organization name that results in RCE through Git hooks
- CVE-2026-25921CRITICAL
Gogs: Cross-repository LFS object overwrite via missing content hash verification
- CVE-2025-64111CRITICAL
Gogs's update .git/config file allows remote command execution
- CVE-2026-52805HIGH
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft
- CVE-2025-64175HIGH
Gogs Vulnerable to 2FA Bypass via Recovery Code
Check if you're affected
Scan your dependencies to see if this vulnerability affects your projects.
Scan Your Dependencies