logo

Attackers Exploited Gogs Zero-Day Flaw for Months

ID: ec6d97b7-bc20-5730-8258-eddeb5ad436d

STIX ID: report--ec6d97b7-bc20-5730-8258-eddeb5ad436d

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-12-11

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

# Executive Summary Wiz disclosed CVE-2025-8110, a remote code execution flaw in Gogs that bypasses a prior path-validation fix through symbolic link abuse; attackers can write outside the repository via the PutContents API, enabling file overwrite and code execution. Active, automated "smash-and-grab" exploitation began July 10, with Wiz finding ~1,400 internet-exposed instances and more than 700 compromised (patterns include random 8-character repo names and unexpected PutContents calls), Supershell seen on infected hosts, and no patch available—mitigations include disabling open registration, reducing internet exposure, and monitoring for the described IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.