Back to Database
Status published
High
CVE-2025-68939
Gitea before 1.23.0 allows attackers to add attachments with forbidden...
Vulnerability Description
Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-68939
Credits & Attribution
No credits recorded in the NVD database.
References
More from Gitea
View All →CVE-2025-69413
In Gitea before 1.25.2, /api/v1/user has different responses for failed...
Medium
5.3
CVE-2025-68946
In Gitea before 1.20.1, a forbidden URL scheme such as...
Medium
5.4
CVE-2025-68945
In Gitea before 1.21.2, an anonymous user can visit a...
Medium
5.8
CVE-2025-68944
Gitea before 1.22.2 sometimes mishandles the propagation of token scope...
Medium
5
CVE-2025-68943
Gitea before 1.21.8 inadvertently discloses users' login times by allowing...
Medium
5.3
Affected Vendor
Gitea
View all reports →Affected Software
Gitea
Vulnerable Versions:
0
Timeline
Official Publish:
December 26th, 2025
Last Modified:
December 26th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.