A critical vulnerability, tracked as CVE-2025-8110, has been identified in the PutContents API of the Gogs self-hosted Git service. The flaw arises from improper handling of symbolic links, allowing remote, authenticated attackers to overwrite arbitrary files on the server. Successful exploitation enables attackers to execute arbitrary code with the privileges of the Gogs server process, potentially leading to full system compromise. Security researchers have reported that this vulnerability is being actively exploited in the wild, and it affects Gogs versions 0.13.3 and prior.
Currently, there is no patched version available to address CVE-2025-8110. Administrators are advised to disable auto-registration of users and avoid exposing Gogs instances to the internet as temporary mitigations. Detection of vulnerable systems can be performed using specific queries to identify Gogs installations, such as searching for HTTP services with a known favicon hash. Organizations running Gogs should prioritize mitigation steps to reduce the risk of exploitation until an official fix is released.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
In an oss-security follow-up on December 11, 2025, a Forgejo developer said the relevant code in Gitea, and therefore Forgejo, had previously been rewritten and attack attempts had not succeeded. This indicated the notable Gogs forks were most likely not affected by CVE-2025-8110.
Public reporting on December 10-11, 2025 tied the exploitation to Supershell C2 malware and estimated that over 700 of roughly 1,400-1,500 internet-facing Gogs instances showed signs of compromise. Researchers said the attacks appeared opportunistic, widespread, and likely run by a single actor or group.
On December 10, 2025, CVE-2025-8110 was formally published with high-severity scoring and descriptions of the PutContents API symlink handling flaw in Gogs. Public proof-of-concept and technical details were also referenced by vulnerability feeds.
Wiz published research on December 10, 2025 describing CVE-2025-8110 as an actively exploited Gogs zero-day affecting version 0.13.3 and earlier. The disclosure said more than 700 public-facing instances had been compromised, no patch was yet available, and published indicators of compromise and mitigations were provided.
Researchers observed a renewed wave of exploitation starting on November 1, 2025, showing the campaign was ongoing months after initial abuse began. Reports describe the activity as automated and likely conducted by a single actor or group.
According to later reporting, Gogs maintainers acknowledged Wiz's report in October 2025, but no patch had been released at that time. The issue remained unresolved despite prior responsible disclosure.
Evidence cited by multiple reports indicates exploitation began around July 2025, including suspicious repositories with random eight-character names created around July 10. The campaign targeted internet-exposed Gogs instances with open registration enabled.
Wiz Research discovered CVE-2025-8110 in Gogs during a malware investigation and responsibly disclosed the issue to Gogs maintainers in July 2025. The flaw is a symlink-based bypass of the earlier CVE-2024-55947 protections and can lead to remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
19 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcewiz.io
Open sourcewiz.io
Open sourcesecalerts.co
Open sourcetenable.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.