GHSA-h697-89cp-24q8CriticalCVSS 9.1

Gitea template repository generation follows unsafe filesystem paths

Published
July 3, 2026
Last Modified
September 1, 2026

🔗 CVE IDs covered (1)

📋 Description

Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processing to read or write through symlinked or otherwise non-regular paths.

🎯 Affected products1

  • go/code.gitea.io/gitea:< 1.25.5

🔗 References (8)