Gogs Path Traversal Vulnerability

Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution.

Published 10 Dec 2025Updated 17 Jun 202623 sources
CVSS 8.7 ✓ VERIFIED REFERENCE△ CISA KEV

Source timeline

Discovered through CISA Known Exploited VulnerabilitiesView source ↗
CVE record published by NVDView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗