VDB
BIT-GITEA-2025-68939
BIT-GITEA-2025-68939
PUBLISHED
CVSS 8.199999809265137 HIGH
Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.
Risk Scores
CVSS 3.1
8.199999809265137
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| gitea | gitea | 0 |
| Gitea | Gitea | 0 |
Timeline
- Dec 26, 2025 CVE Published
- Dec 26, 2025 PoC Published
- Dec 26, 2025 CVE Updated
- Jan 2, 2026 PoC Published