logo

U.S. CISA adds a flaw in Gogs to its Known Exploited Vulnerabilities catalog

ID: 8a76846e-6796-563e-84c3-d7cc8a849d8a

STIX ID: report--8a76846e-6796-563e-84c3-d7cc8a849d8a

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-01-12

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CISA added CVE-2025-8110 — a Gogs symlink handling/path traversal flaw enabling authenticated remote code execution — to its Known Exploited Vulnerabilities catalog after Wiz researchers, investigating a malware incident, found active exploitation and identified roughly 1,400 exposed instances with over 700 compromised. The vulnerability bypasses an earlier patch by leveraging Git symlinks to overwrite files outside repositories; agencies are directed to remediate by the CISA deadline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.