• News/
  • https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-gogs-rce-flaw-exploited-in-zero-day-attacks/

CISA orders feds to patch Gogs RCE flaw exploited in zero-day attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Jan 12, 2026
·
Updated

​The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered government agencies to secure their systems against a high-severity Gogs vulnerability that was exploited in zero-day attacks. Designed as an alternative to GitLab or GitHub Enterprise and written in Go, Gogs is often exposed online for remote collaboration. Tracked as CVE-2025-8110, this remote code execution (RCE) security flaw stems from a path traversal weakness in the PutContents API and allows authenticated attackers to bypass protections implemented for a previously patched RCE bug (CVE-2024-55947) by overwriting files outside the repository via symbolic links. Attackers can abuse this flaw by creating repos containing symbolic links pointing to sensitive system files, and then writing data through the symlink using the PutContents API, overwriting targets outside the repository. By overwriting Git configuration files, specifically the sshCommand setting, threat actors can force target systems to execute arbitrary commands. Wiz Research discovered the vulnerability while investigating a malware infection affecting a customer's Internet-facing Gogs server in July and reported the flaw to Gogs maintainers on July 17. They acknowledged Wiz's report three months later, on October 30, and released patches for CVE-2025-8110 last week that add symlink-aware path validation at all file-write entry points. According to a disclosure timeline shared by Wiz Research, a second wave of attacks targeting t...

Read full article

Affected Software

1 affected component
Gogs Gogs=*
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the CISA's order for U.S. government agencies to patch a critical RCE vulnerability in Gogs software that has been exploited in zero-day attacks.

2

What security implications are discussed in the article?

The article highlights the risk posed by a high-severity vulnerability in Gogs that could lead to unauthorized remote code execution.

3

What products or software are affected?

The affected software mentioned in the article is Gogs, which is an open-source Git service.

4

Who issued the directive for patching the vulnerability?

The directive to patch the vulnerability was issued by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

5

What should agencies do in response to this vulnerability?

Agencies are instructed to secure their systems by applying the necessary patches to mitigate the Gogs RCE vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203