Insufficient Branch Deletion Permissions in Gitea by Gitea Team
CVE-2025-68940
3.1LOW
What is CVE-2025-68940?
In Gitea, prior to version 1.22.5, there is a vulnerability related to insufficient enforcement of branch deletion permissions post-pull request merge. This could potentially allow unauthorized users to delete branches even after they have been merged, leading to disruption in workflow and compromise of code integrity. Users are advised to update to the latest version to safeguard their repositories.
Affected Version(s)
Gitea 0 < 1.22.5
