Unauthorized Access Vulnerability in Gitea by Gitea
CVE-2025-68945

5.8MEDIUM

Key Information:

Vendor

Gitea

Status
Vendor
CVE Published:
26 December 2025

What is CVE-2025-68945?

An unauthorized access vulnerability exists in Gitea versions prior to 1.21.2, where an anonymous user can gain access to private user projects. This flaw could potentially expose sensitive project information, highlighting the importance of promptly updating to the latest version to secure user data and maintain project confidentiality.

Affected Version(s)

Gitea 0 < 1.21.2

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-68945 : Unauthorized Access Vulnerability in Gitea by Gitea