Components
Vulnerabilities
Pricing
MCP
Docs
Sign up
Login
Find vulnerabilities. Fix fast with AI.
Search components by package, version, or CVE to get started.
Ecosystem
Package
Version
Vulnerabilities
CVE-2025-8110
CVE-2025-8110
EXPLOITED
Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
Published Dec 11, 2025
https://github.com/advisories/GHSA-mq8m-42gh-wq7r
CVSS Score
High
8.8
Components Impacted
Components Impacted
Security Details
Security Details
Sonatype Research
Sonatype Research
Ecosystem
Package
Version
Ecosystem
Package
Version
golang
gogs.io/gogs
v0.12.0
golang
gogs.io/gogs
v0.12.10-rc.1
golang
gogs.io/gogs
v0.12.10
golang
gogs.io/gogs
v0.12.11-rc.1
golang
gogs.io/gogs
v0.12.11
golang
gogs.io/gogs
v0.12.1
golang
gogs.io/gogs
v0.12.2
golang
gogs.io/gogs
v0.12.3
golang
gogs.io/gogs
v0.12.4-rc.1
golang
gogs.io/gogs
v0.12.4
golang
gogs.io/gogs
v0.12.5-rc.1
golang
gogs.io/gogs
v0.12.5
golang
gogs.io/gogs
v0.12.6-rc.1
golang
gogs.io/gogs
v0.12.6
golang
gogs.io/gogs
v0.12.7-rc.1
golang
gogs.io/gogs
v0.12.7
golang
gogs.io/gogs
v0.12.8-rc.1
golang
gogs.io/gogs
v0.12.8
golang
gogs.io/gogs
v0.12.9-rc.1
golang
gogs.io/gogs
v0.12.9
golang
gogs.io/gogs
v0.13.0-rc.1
golang
gogs.io/gogs
v0.13.0
golang
gogs.io/gogs
v0.13.1-rc.1
golang
gogs.io/gogs
v0.13.1
golang
gogs.io/gogs
v0.13.2-rc.1
golang
gogs.io/gogs
v0.13.2
golang
gogs.io/gogs
v0.13.3-rc.1
golang
gogs.io/gogs
v0.13.3
1-28 of 28
CVE-2025-8110 | Components Impacted | Sonatype Guide | Sonatype Guide