Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
02 / AFFECTED SOFTWARE
Affected packages
36 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text.
Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text.
Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text.
05 / REFERENCES
Further evidence
- https://blog.gitea.com/release-of-1.22.2/
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68942.json
- https://github.com/go-gitea/gitea/pull/31966
- https://github.com/go-gitea/gitea/releases/tag/v1.22.2
- https://nvd.nist.gov/vuln/detail/CVE-2025-68942
- https://blog.gitea.com/release-of-1.22.2
- https://github.com/advisories/GHSA-898p-hh3p-hf9r
- https://github.com/go-gitea/gitea