Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that government agencies secure their systems against a critical Gogs vulnerability, tracked as CVE-2025-8110. This remote code execution (RCE) flaw, stemming from a path traversal weakness in the PutContents API, has been...
A zero-day vulnerability in Gogs, identified as CVE-2025-8110, is being actively exploited, allowing authenticated users to execute remote code. This flaw affects over 50% of public-facing Gogs instances, and as of now, no patch is available to mitigate the issue.
A critical argument injection vulnerability (CWE-88) has been discovered in Gogs, a widely used self-hosted Git service, allowing authenticated users to execute arbitrary code on the server. The flaw, identified by Rapid7's Jonah Burgess, has a CVSSv4 score of 9.4 and affects Gogs versions 0.14.2 an...
A zero-day vulnerability in Gogs, a self-hosted Git service, is being actively exploited, affecting over 700 instances. Discovered by Wiz Research during a malware investigation, the vulnerability allows authenticated users to execute remote code by overwriting files outside the repository. As of De...