Gogs Zero-Day Exploited in 700+ Instances
These articles are AI-generated summaries. Please check the original sources for full details.
Gogs Zero-Day Exploited in 700+ Instances
A critical zero-day vulnerability (CVE-2025-8110) in the self-hosted Git service Gogs is being actively exploited, impacting over 700 publicly accessible instances. The flaw, with a CVSS score of 8.7, allows attackers to overwrite files and achieve remote code execution.
Why This Matters
Ideal security models assume prompt patching, but real-world deployment lags expose systems to known and zero-day vulnerabilities. This Gogs flaw, bypassing a previous fix (CVE-2024-55947), demonstrates the risk of incomplete mitigation and the potential for widespread compromise – over 700 instances affected represent a significant attack surface and potential data breach risk.
Key Insights
- CVE-2025-8110: File overwrite vulnerability in Gogs, discovered in July 2025.
- Symlink Bypass: Attackers circumvented a prior patch by exploiting Git’s symbolic link handling within the Gogs API.
- Supershell C2: The malware deployed in the attacks utilizes the Supershell command-and-control framework, often associated with Chinese hacking groups.
Practical Applications
- Use Case: Attackers are leveraging the vulnerability for “smash-and-grab” style attacks, deploying malware and establishing reverse SSH shells.
- Pitfall: Relying on a single patch without accounting for underlying protocol vulnerabilities (like symlink handling) can lead to bypasses and continued exploitation.
References:
Continue reading
Next article
Why Developers Hate Jira and How to Make It Dev-Friendly Again
Related Content
.NET SOAPwn Flaw Opens Door for File Writes and Remote Code Execution via Rogue WSDL
New research reveals a .NET flaw, SOAPwn, enables file writes and remote code execution (RCE) through manipulated WSDL files in products like Barracuda and Ivanti.
Critical n8n Flaw (CVSS 9.9) Enables Arbitrary Code Execution
A critical n8n vulnerability (CVE-2025-68613, CVSS 9.9) allows authenticated users to execute arbitrary code, impacting over 100,000 instances.
CISA Adds Actively Exploited Sierra Wireless Router Flaw Enabling RCE Attacks
CISA warns of active exploitation of Sierra Wireless router flaw allowing remote code execution via unrestricted file upload.