ZeroHour

CVE-2025-68939

CVSS 3.1
5.3 medium
EPSS
<1%p27
Published
()
Modified
Description

Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.

Vendors
gitea
Products
gitea
Weakness
CWE-424
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.