GHSA-mq8m-42gh-wq7r
Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2025-8110, https://github.com/gogs/gogs/pull/8078, https://github.com/gogs/gogs/pull/8082, https://github.com/advisories/GHSA-mq8m-42gh-wq7r, https://github.com/gogs/gogs, http://wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploit, http://www.openwall.com/lists/oss-security/2025/12/11/3, http://www.openwall.com/lists/oss-security/2025/12/11/4
