Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2025-8110] Gogs 0-Day Exploited in the Wild

wiz.io | vulnerability | CVE-2025-8110 | #rce | #zero-day | #vulnerability | #symlink | #gogs | #cve-2025-8110 | #git-service

Summary

Wiz found Gogs zero-day CVE-2025-8110 exploited in the wild: a symlink bypass of the CVE-2024-55947 fix lets authenticated users write outside the repo for RCE; 700+ instances hit, fixed in v0.13.4.
Published
Collected

original ↗

Related coverage

back