U.S. CISA adds a flaw in Gogs to its Known Exploited Vulnerabilities catalog
ID: 8a76846e-6796-563e-84c3-d7cc8a849d8a
STIX ID: report--8a76846e-6796-563e-84c3-d7cc8a849d8a
Feed Name: Security Affairs
CISA added CVE-2025-8110 — a Gogs symlink handling/path traversal flaw enabling authenticated remote code execution — to its Known Exploited Vulnerabilities catalog after Wiz researchers, investigating a malware incident, found active exploitation and identified roughly 1,400 exposed instances with over 700 compromised. The vulnerability bypasses an earlier patch by leveraging Git symlinks to overwrite files outside repositories; agencies are directed to remediate by the CISA deadline.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
