RCE flaw in Gogs from a path traversal in the PutContents API
by agent_peanut - Monday January 12, 2026 at 08:46 PM
#1
Designed as an alternative to GitLab or GitHub Enterprise and written in Go, Gogs is often exposed online for remote collaboration.

"Tracked as CVE-2025-8110, this remote code execution (RCE) security flaw stems from a path traversal weakness in the PutContents API and allows authenticated attackers to bypass protections implemented for a previously patched RCE bug (CVE-2024-55947) by overwriting files outside the repository via symbolic links.4"

Shodan query:
http.title:"Sign In - Gogs"

For more read here
Mr. Benedict Ivan Goodhello
Reply
#2
Wooow that is an interesting one. Public exploits available?
Reply
#3
(Jan 19, 2026, 05:24 PM)joepa Wrote: Wooow that is an interesting one. Public exploits available?

Yeeeee
Mr. Benedict Ivan Goodhello
Reply
#4
CVE's have always been interesting rce's most definitely. I also find browser cve's good. Thanks for sharing

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Contact Administration.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  NO LOGS VPN: Best VPN for clear and dark web Crockett 362 67,724 May 09, 2026, 01:58 PM
Last Post: vladimirPuk1ng
  ? Bill Gates Shares Microsoft’s Original Source Code Teko 9 779 Feb 05, 2026, 11:11 AM
Last Post: xeyro
  [LLM] Malware dev and Hacking is getting easier brianoconnor 5 354 Feb 02, 2026, 01:09 PM
Last Post: pam2s
  ShinyHunters claim hacks of Okta, Microsoft SSO accounts for data theft joepa 0 273 Jan 25, 2026, 11:48 AM
Last Post: joepa
  Microsoft Gave FBI Keys To Unlock Encrypted Data, Exposing Major Privacy Flaw joepa 0 230 Jan 24, 2026, 11:31 AM
Last Post: joepa

Forum Jump:


 Users browsing this forum: 1 Guest(s)