CVE-2025-68937: Forgejo

Critical severity, CVSS 9.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of mishandling of out-of-repository symlink destinations for template repositories. This is also fixed for 11 LTS in 11.0.7 and later.

Affected products

  • Forgejo Forgejo: from 12.0.0, before 13.0.2 (fixed in 13.0.2); before 11.0.7 (fixed in 11.0.7)

Published 2025-12-26. Last modified 2026-06-17.