CVE-2025-68939: Gitea

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.

Affected products

  • Gitea Gitea: before 1.23.0 (fixed in 1.23.0)

Published 2025-12-26. Last modified 2026-06-17.