
Proof-of-concept exploit for CVE-2025-8110 in Gogs <=0.13.x, enabling authenticated symlink bypass to arbitrary file write as the Gogs process user, leading to local privilege escalation.
Gogs <= 0.13.x. An authenticated user commits a symlink into a repository, then
calls the "update file contents" API
(PUT /api/v1/repos/<u>/<r>/contents/<path>). Gogs follows the symlink and
writes attacker-controlled bytes to the link target with the privileges of the
Gogs process. When Gogs runs as root this is an arbitrary root file write -
e.g. drop a NOPASSWD rule into /etc/sudoers.d/ for local privilege
escalation.
Reported by Wiz Research.
CVE: CVE-2025-8110
python3 -m pip install requests pillow # gogs_register.py (captcha OCR)
# plus a `tesseract` binary on PATH (or edit the R= path in gogs_register.py)
gogs_register.py - get an authenticated account past the signup captchapython3 gogs_register.py [username] [password] # defaults: pocuser / PocPass123!
# targets http://127.0.0.1:3001 - edit B= for a remote instance
gogs_symlink_root.sh - the symlink write./gogs_symlink_root.sh <gogs-user> <gogs-pass> [sudo-user]
# sudo-user defaults to the current user; writes /etc/sudoers.d/<sudo-user>
# run on the target host (git + curl available, Gogs reachable on 127.0.0.1:3001)
For authorised security testing and education only. Only run this against systems you own or have explicit written permission to test.
Author: r3vpwnx