References https://avd.aliyun.com/detail?id=AVD-2022-2024 https://github.com/111ddea/goga-cve-2025-8110/blob/main/CVE-2025-8110-verification-report.md https://cloud.tencent.com/developer/article/2619558 https://www.ihonker.com/thread-34114-1-1.html https://www.ithome.com.tw/news/166703 https://wiki.96.mk/Web%E5%AE%89%E5%85%A8/Gogs/%EF%BC%88CVE-2018-18925%EF%BC%89Gogs%20%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B7%E7%99%BB%E5%BD%95%E6%BC%8F%E6%B4%9E/ https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/webapp/Gogs-%E7%AC%A6%E5%8F%B7%E9%93%BE%E6%8E%A5%E5%AF%BC%E8%87%B4%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E-CVE-2025-8110.md https://www.gm7.org/archives/17311 https://www.secrss.com/articles/80196 https://nvd.nist.gov/vuln/detail/CVE-2025-64111 https://www.wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploit https://www.appsecure.security/vulnerability-database/cve-2025-8110/ https://github.com/zAbuQasem/gogs-CVE-2025-8110 https://www.secrss.com/articles/85951
Related VulnerabilitiesPoCCVE-2026-52806: Gogs <= 0.14.2 - Authenticated RCE via git rebase Argument InjectionGogs /api/v1/orgs/:orgname/teams 信息泄露漏洞(CVE-2026-52815)PoCCVE-2026-52815: Gogs < 0.14.3 - Unauthenticated Organization Teams DisclosurePoCCVE-2025-8110: Gogs <= 0.13.3 - Remote Code ExecutionPoCCVE-2014-8682: Gogs (Go Git Service) - SQL InjectionPoCCVE-2018-18925: Gogs (Go Git Service) 0.11.66 - Remote Code ExecutionPoCCVE-2020-15867: Gogs 0.5.5 - 0.12.2 - Remote Code ExecutionPoCCVE-2022-0415: Gogs <0.12.6 - Remote Command ExecutionPoCCVE-2022-0870: Gogs <0.12.5 - Server-Side Request ForgeryPoCgogs-installer: Gogs (Go Git Service) - InstallerGogs远程命令执行漏洞Gogs 弱口令漏洞Gogs Full Name 存储型XSS漏洞