Over 700 Gogs Instances Exploited via Critical CVE-2025-8110 Flaw

Critical Gogs Git Service Vulnerability CVE-2025-8110 Enables Remote Code Execution via Symbolic Link Exploit and Active Malware Campaign

  • A high-severity vulnerability in the self-hosted Git service Gogs is actively exploited, affecting over 700 internet-accessible instances.
  • The flaw, CVE-2025-8110, enables arbitrary file overwrite via symbolic link mishandling, leading to remote code execution.
  • The exploit bypasses a previous fix for CVE-2024-55947, leveraging Gogs API and Git symbolic links to overwrite sensitive files.
  • Attackers deploy Supershell-based Malware to establish reverse SSH shells to their servers.
  • Users are advised to disable open registration, restrict internet exposure, and scan for suspicious repositories until a patch is available.

A critical unpatched security flaw in the Go-based self-hosted Git service Gogs has been discovered to be under active exploitation as of mid-2025. The vulnerability, tracked as CVE-2025-8110 and rated with a CVSS score of 8.7, allows attackers to overwrite arbitrary files on affected servers. Over 1,400 exposed instances exist online, with more than 700 showing signs of compromise, according to findings from security researchers at Wiz.

- Advertisement -

This vulnerability arises from improper handling of symbolic links in the PutContents API of Gogs, enabling local code execution. It effectively bypasses a patch implemented in December 2024 for CVE-2024-55947, which previously addressed remote code execution but did not account for symbolic link exploitation. Attackers exploit this by creating a git repository with a symbolic link targeting sensitive files, then use the API to overwrite those targets outside the repository. This process allows modification of the “.git/config” file, specifically the sshCommand, to execute arbitrary server commands.

The malware used in these attacks is based on Supershell, an open-source command-and-control (C2) framework often linked to Chinese Hacking groups. It establishes reverse SSH shells connecting to attacker-controlled servers, such as the IP address “119.45.176[.]196”. Researchers noted that the attackers left behind the created repositories, which feature random 8-character owner and repository names, suggesting a rapid, opportunistic campaign.

Currently, there is no official fix for CVE-2025-8110. Users of Gogs are urged to disable open-registration features, reduce exposure to the internet, and scan for repositories matching the compromise profile. The vulnerability was initially found in July 2025 during the investigation of a malware infection on a customer system.

Separately, there is a growing concern as threat actors increasingly exploit leaked GitHub Personal Access Tokens (PATs) to gain initial access to cloud environments. These tokens can be abused to locate secret keys embedded in GitHub workflow files and execute malicious code. According to researcher Shira Ayal, attackers have used compromised PATs to discover GitHub Action secrets and utilize them for further cloud service provider credential access, while evading detection through covert exfiltration techniques.

- Advertisement -

For more details about the exploit and mitigation, refer to the original Wiz report and the CVE description on CVE.org.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Nvidia’s OpenAI Investment Could Be Its Last Before IPO

NVIDIA CEO Jensen Huang indicated the company's recent $30 billion investment in OpenAI may...

Bitcoin Outperforms Oil, Gold in US-Iran War Shock

Bitcoin has surged 12.1% since the onset of the US-Israeli conflict with Iran, outperforming...

Tradeweb Leads $31M Crypto Platform Crossover Series B

Tradeweb is leading a $31 million Series B in Crossover Markets, valuing the crypto...

Crypto Stocks Surge After Trump Backs Bitcoin Bill

Coinbase stock surged over 15% after former President Donald Trump expressed support for a...

Kraken Gets Fed Master Account, Banks Cry Foul

Kraken secured a Federal Reserve master account on Wednesday, becoming the first crypto bank...

Must Read

Are Cryptocurrency Securities?

TL;DR - Cryptocurrencies are not typically considered securities, as they are decentralized digital assets that operate independently of any central authority or government. However,...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!