CVE-2025-68937: Forgejo
Critical severity, CVSS 9.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of mishandling of out-of-repository symlink destinations for template repositories. This is also fixed for 11 LTS in 11.0.7 and later.
Affected products
- Forgejo Forgejo: from 12.0.0, before 13.0.2 (fixed in 13.0.2); before 11.0.7 (fixed in 11.0.7)
Published 2025-12-26. Last modified 2026-06-17.