CVE-2025-68937
Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
26/12/2025
Last modified:
26/12/2025
Description
Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of mishandling of out-of-repository symlink destinations for template repositories. This is also fixed for 11 LTS in 11.0.7 and later.
Impact
Base Score 4.0
9.50
Severity 4.0
CRITICAL
References to Advisories, Solutions, and Tools
- https://blog.gitea.com/release-of-1.24.7/
- https://codeberg.org/forgejo/forgejo/milestone/27340
- https://codeberg.org/forgejo/forgejo/milestone/29156
- https://codeberg.org/forgejo/forgejo/src/branch/forgejo/release-notes-published/11.0.7.md
- https://codeberg.org/forgejo/forgejo/src/branch/forgejo/release-notes-published/13.0.2.md
- https://codeberg.org/forgejo/security-announcements/issues/43



