File Extension Manipulation Vulnerability in Gitea by Gitea Team
CVE-2025-68939
8.2HIGH
What is CVE-2025-68939?
A vulnerability in Gitea prior to version 1.23.0 allows attackers to exploit the attachment API by modifying the names of uploaded attachments. This exploitation enables the inclusion of files with disallowed extensions, potentially leading to significant security risks such as execution of malicious code and unauthorized access.
Affected Version(s)
Gitea 0 < 1.23.0
