blog.gitea.com
https://blog.gitea.com/release-of-1.23.0 CVE-2025-68939
HIGH
Gitea allows attackers to add attachments with forbidden file extensions
Record summary
CVE-2025-68939 has a selected CVSS score of 8.2 (high).
Description
Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 26, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
GiteaBrowse Gitea / GiteaDefault status: unaffected | CVE List | Before 1.23.0 | affected |
code.gitea.io/giteaBrowse Go / code.gitea.io/gitea | GitHub Advisory | All versions | affected |
References
5github.com
https://github.com/go-gitea/gitea github.com
https://github.com/go-gitea/gitea/pull/32151 github.com
https://github.com/go-gitea/gitea/releases/tag/v1.23.0 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-68939