PT-2025-53442 · Gitea · Gitea

Published

2025-12-26

·

Updated

2026-01-06

·

CVE-2025-68944

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Gitea versions prior to 1.22.2
Description A flaw exists in Gitea where the propagation of token scope for access control is improperly handled within its package registries. This can lead to unauthorized access.
Recommendations Update to Gitea version 1.22.2 or later.

Fix

Weakness Enumeration

Related Identifiers

BIT-GITEA-2025-68944
CVE-2025-68944
GHSA-F85H-C7M6-CFPM
GO-2025-4264
SUSE-SU-2026:0037-1

Affected Products

Gitea