CVE-2026-28705

MEDIUM

Gitea repository dumps write release assets using unsafe path names

Title source: cna
STIX 2.1

Description

Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release assets, allowing specially crafted names to affect dump output paths.

References (4)

Core 4
Core References
Patch patch
GitHub Pull Request #36799
https://github.com/go-gitea/gitea/pull/36799
Patch patch
GitHub Pull Request #36839
https://github.com/go-gitea/gitea/pull/36839
Release Notes release-notes
Gitea v1.25.5 Release
https://github.com/go-gitea/gitea/releases/tag/v1.25.5
Release Notes release-notes
Gitea v1.25.5 Release Blog Post
https://blog.gitea.com/release-of-1.25.5/

Scores

CVSS v3 5.3
EPSS 0.0037
EPSS Percentile 29.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
Gitea/Gitea Open Source Git Server < 1.25.5
Published Jul 03, 2026
Tracked Since Jul 04, 2026