VDB

CISA-2025-68941

CISA-2025-68941 PUBLISHED CVSS 4.9 MEDIUM

Reported by mitre · Published December 26, 2025

Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.

Risk Scores

CVSS 3.1
4.9
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N

Affected Products

VendorProductVersions
GiteaGitea0
GiteaGitea0, 0
giteagitea0, 0

Timeline

  • Dec 26, 2025 CVE Published
  • Dec 26, 2025 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›