GHSA-7jvx-g65v-r899MediumCVSS 5.3

Gitea release asset dumps permit path traversal through crafted names

Published
July 3, 2026
Last Modified
September 1, 2026

🔗 CVE IDs covered (1)

📋 Description

Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release assets, allowing specially crafted names to affect dump output paths.

🎯 Affected products1

  • go/code.gitea.io/gitea:< 1.25.5

🔗 References (8)