Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitygovernment-vulnerability-cataloginternet-facing-service-vulnerabilityrapid-weaponization

CISA Flags Actively Exploited Gogs Path Traversal Leading to RCE (CVE-2025-8110)

Updated 3mo agoFirst seen Jan 12, 20266 sources

CISA added CVE-2025-8110 affecting the Gogs self-hosted Git service to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation and triggering mandatory remediation timelines for U.S. Federal Civilian Executive Branch (FCEB) agencies under BOD 22-01. The issue is described as a path traversal weakness that can be leveraged for remote code execution (RCE) in real-world attacks, increasing risk for organizations running Internet-exposed Gogs instances.

Technical reporting indicates the flaw resides in the PutContents API and can be abused by authenticated attackers using symbolic links to write outside a repository and overwrite sensitive files; one described route to code execution is overwriting Git configuration (e.g., sshCommand) to force arbitrary command execution. Wiz Research tied the vulnerability to observed malware activity on an Internet-facing Gogs server and reported large-scale exposure and compromise signals across the ecosystem (including thousands of exposed servers and hundreds showing signs of compromise), with exploitation observed as a zero-day prior to patch availability; CISA’s KEV action formalizes the exploitation status and elevates patching priority for both government and non-government operators.

Share:
CISA Flags Actively Exploited Gogs Path Traversal Leading to RCE (CVE-2025-8110)
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Jan 12, 20265mo ago

CISA orders federal agencies to remediate Gogs flaw by Feb. 2

With the KEV listing, CISA directed Federal Civilian Executive Branch agencies to remediate CVE-2025-8110 under Binding Operational Directive 22-01 by February 2, 2026. Guidance also included mitigations such as disabling open registration and restricting access to Gogs instances.

CISA adds CVE-2025-8110 to the KEV catalog

On January 12, 2026, CISA added the actively exploited Gogs vulnerability CVE-2025-8110 to its Known Exploited Vulnerabilities catalog. CISA said the flaw posed significant risk and urged organizations to prioritize remediation.

Jan 5, 20266mo ago

Patches for CVE-2025-8110 are released

Gogs released patches for CVE-2025-8110 in early January 2026, about a week before CISA's KEV announcement. The fixes addressed the symlink-based path traversal that enabled remote code execution.

Dec 1, 20257mo ago

Wiz reports large-scale exposure and compromise of Gogs servers

By late 2025, Wiz reported that roughly 1,400 Gogs instances were exposed to the internet and more than 700 public-facing instances showed signs of compromise. The company said the exploitation appeared widespread and likely driven by a single actor or toolset.

Nov 1, 20258mo ago

Wiz observes second wave of zero-day exploitation

On November 1, 2025, Wiz observed a second wave of in-the-wild exploitation targeting internet-facing Gogs instances. The activity appeared automated and involved indicators such as suspicious repositories with random eight-character names.

Oct 30, 20258mo ago

Gogs maintainers acknowledge the vulnerability report

Gogs maintainers acknowledged Wiz's report of CVE-2025-8110 on October 30, 2025. This marked the vendor's formal recognition of the issue before broader disclosure and remediation guidance.

Jul 17, 202511mo ago

Wiz reports CVE-2025-8110 to Gogs maintainers

Wiz reported the newly discovered Gogs vulnerability to the project's maintainers on July 17, 2025. The flaw was described as a bypass of the earlier CVE-2024-55947 fix through improper symbolic link handling.

Jul 1, 20251y ago

Wiz discovers Gogs flaw during July malware investigation

Wiz Research identified CVE-2025-8110, a path traversal and symlink-handling flaw in Gogs' PutContents API, while investigating a malware infection on an internet-facing Gogs server in July 2025. The issue could let authenticated attackers write outside a repository and achieve remote code execution.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.