CISA Flags Actively Exploited Gogs Vulnerability With No Patch
ID: a14e8286-20c2-5de8-ab1b-e0be22828680
STIX ID: report--a14e8286-20c2-5de8-ab1b-e0be22828680
Feed Name: Infosecurity Magazine (News)
A high-severity Gogs vulnerability (CVE-2025-8110, CVSS 8.7) that enables symlink-based file overwrite and remote code execution is being actively exploited; researchers observed more than 700 compromised instances and Censys reports ~1,602 internet-exposed Gogs servers. CISA added the flaw to its KEV catalog, no official patch is yet widely available, and attackers have deployed Supershell C2-linked malware; immediate mitigations (disable open registration, restrict access, monitor anomalous repos/API usage) are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
