PT-2025-53436 · Gitea+1 · Gitea+1

Published

2025-12-26

·

Updated

2026-02-24

·

CVE-2025-68939

CVSS v3.1

8.2

High

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Gitea versions prior to 1.23.0
Description A flaw exists that enables attackers to add attachments with file extensions that are normally prohibited. This is achieved by modifying the attachment name through the attachment API. The affected API endpoint is the attachment API. Attackers manipulate the filename parameter to bypass file extension restrictions.
Recommendations Update to version 1.23.0 or later.

Fix

Weakness Enumeration

Related Identifiers

BIT-GITEA-2025-68939
CVE-2025-68939
GHSA-263Q-5CV3-XQ9G
GO-2025-4261
SUSE-SU-2026:0037-1

Affected Products

Gitea
Red Os