Path Resolution Vulnerability in Gitea Affects Repository Templates
CVE-2026-25718
9.1CRITICAL
What is CVE-2026-25718?
Gitea prior to version 1.25.5 suffers from a flaw in path resolution that impacts the generation of template repositories. This issue can allow for unauthorized reading or writing of data through symlinked and non-standard paths, potentially exposing sensitive information or allowing for malicious file manipulations. Users are advised to upgrade to version 1.25.5 or later to mitigate these risks.
Affected Version(s)
Gitea Open Source Git Server 0 < 1.25.5
