<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Gogs</title><description>Actively exploited vulnerabilities affecting Gogs products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/gogs.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-8110 — Gogs Path Traversal Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-8110</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-8110</guid><description>Gogs, a self-hosted Git service, has a path traversal flaw in its PutContents API caused by improper handling of symbolic links. An attacker who can craft API requests could escape intended directory boundaries, potentially writing or manipulating files outside the repository. This could lead to remote code execution on the host system, making it a serious risk for any organization running Gogs as part of their development infrastructure.</description><pubDate>Mon, 12 Jan 2026 00:00:00 GMT</pubDate><category>Gogs</category><category>Gogs</category></item></channel></rss>