CVE Vulnerabilities

CVE-2025-68939

Improper Protection of Alternate Path

Published: Dec 26, 2025 | Modified: Jan 02, 2026
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
8.2 IMPORTANT
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.

Weakness

The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.

Affected Software

NameVendorStart VersionEnd Version
GiteaGitea*1.23.0 (excluding)

Potential Mitigations

References