<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/cisa-warns-of-active-exploitation-of-gogs-vulnerability-enabling-code-execution-qwukvwdsk" -->

---
title: CISA Warns of Active Exploitation of Gogs Vulnerability...
description: CISA has added CVE-2025-8110, a high-severity path traversal vulnerability in Gogs, to its Known Exploited Vulnerabilities catalog after detecting active...
canonical: https://daily.dev/posts/cisa-warns-of-active-exploitation-of-gogs-vulnerability-enabling-code-execution-qwukvwdsk
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: CISA Warns of Active Exploitation of Gogs Vulnerability Enabling Code Execution | daily.dev
og:description: CISA has added CVE-2025-8110, a high-severity path traversal vulnerability in Gogs, to its Known Exploited Vulnerabilities catalog after detecting active...
og:url: https://daily.dev/posts/cisa-warns-of-active-exploitation-of-gogs-vulnerability-enabling-code-execution-qwukvwdsk
og:image: https://api.daily.dev/og/posts/QWUKVWdsK.png
og:image:alt: CISA Warns of Active Exploitation of Gogs Vulnerability Enabling Code Execution
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# CISA Warns of Active Exploitation of Gogs Vulnerability Enabling Code Execution

**[The Hacker News](https://daily.dev/sources/thn)** · 2 min read · 0 upvotes · 0 comments

## Summary

CISA has added CVE-2025-8110, a high-severity path traversal vulnerability in Gogs, to its Known Exploited Vulnerabilities catalog after detecting active exploitation. The flaw allows attackers to bypass symbolic link protections and achieve remote code execution by overwriting Git configuration files. Approximately 700 Gogs instances have been compromised, with 1,600 servers exposed online. No official patch is available yet, though code fixes are pending. Users should disable open registration and restrict server access via VPN or allow-lists until patches are released.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://thehackernews.com/2026/01/cisa-warns-of-active-exploitation-of.html>

## Similar posts on daily.dev

- [Fed agencies urged to ditch Gogs as zero-day makes CISA list](https://daily.dev/posts/fed-agencies-urged-to-ditch-gogs-as-zero-day-makes-cisa-list-ivq9zu10p) · The Register · 1 upvotes · 0 comments
- [Lack of response to critical vulnerability in Gogs is a reminder of the limits of open source projects](https://daily.dev/posts/lack-of-response-to-critical-vulnerability-in-gogs-is-a-reminder-of-the-limits-of-open-source-projec-v3gxoylqb) · InfoWorld · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#devops](https://daily.dev/tags/devops), [#git](https://daily.dev/tags/git), [#vulnerability](https://daily.dev/tags/vulnerability)

[View this post on daily.dev](https://daily.dev/posts/cisa-warns-of-active-exploitation-of-gogs-vulnerability-enabling-code-execution-qwukvwdsk)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"CISA Warns of Active Exploitation of Gogs Vulnerability Enabling Code Execution","url":"https://daily.dev/posts/cisa-warns-of-active-exploitation-of-gogs-vulnerability-enabling-code-execution-qwukvwdsk","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/cisa-warns-of-active-exploitation-of-gogs-vulnerability-enabling-code-execution-qwukvwdsk"},"datePublished":"2026-01-13T08:14:42.091Z","dateModified":"2026-01-13T08:15:00.393Z","description":"CISA has added CVE-2025-8110, a high-severity path traversal vulnerability in Gogs, to its Known Exploited Vulnerabilities catalog after detecting active...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/94c105098365bb386196eef1bea30802?_a=AQAEulh","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/94c105098365bb386196eef1bea30802?_a=AQAEulh","isAccessibleForFree":true,"articleSection":"The Hacker News","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"The Hacker News","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/thn","url":"https://daily.dev/sources/thn"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/cisa-warns-of-active-exploitation-of-gogs-vulnerability-enabling-code-execution-qwukvwdsk","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,devops,git,vulnerability","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"The Hacker News","item":"https://daily.dev/sources/thn"},{"@type":"ListItem","position":3,"name":"CISA Warns of Active Exploitation of Gogs Vulnerability Enabling Code Execution"}]}
```

