All verified exploits

CVE-2025-8110 Symlink Path Traversal RCE

Deterministic critical Gogs Added cve-verified-cve-2025-8110

Detects vulnerable Gogs versions where the repository editor API follows symlinks without checking directory components. Any authenticated user can overwrite arbitrary files via symlink traversal and inject commands into .git/config for remote code execution.

Is your app exploitable through CVE-2025-8110?

Scan your domain free