Gitea allows attackers to add attachments with forbidden file extensions
Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.
02 / AFFECTED SOFTWARE
Affected packages
34 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.
Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.
Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.
05 / REFERENCES
Further evidence
- https://blog.gitea.com/release-of-1.23.0/
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68939.json
- https://github.com/go-gitea/gitea/pull/32151
- https://github.com/go-gitea/gitea/releases/tag/v1.23.0
- https://nvd.nist.gov/vuln/detail/CVE-2025-68939
- https://blog.gitea.com/release-of-1.23.0
- https://github.com/go-gitea/gitea
- https://github.com/advisories/GHSA-263q-5cv3-xq9g