{"id":"CVE-2025-68939","aliases":["GHSA-263q-5cv3-xq9g","BIT-gitea-2025-68939","GO-2025-4261"],"title":"Gitea allows attackers to add attachments with forbidden file extensions","summary":"Gitea allows attackers to add attachments with forbidden file extensions","severity":"high","cvss":8.2,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L","vendor":"gitea","product":"code.gitea.io/gitea","ecosystem":"go","affected":["code.gitea.io/gitea"],"published":"2025-12-26","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:31.291622959Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-263q-5cv3-xq9g","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68939"},{"url":"https://github.com/go-gitea/gitea/pull/32151"},{"url":"https://blog.gitea.com/release-of-1.23.0"},{"url":"https://github.com/go-gitea/gitea"},{"url":"https://github.com/go-gitea/gitea/releases/tag/v1.23.0"}],"tags":["osv","go"],"epss":0.00332,"epssPercentile":0.26587,"ingestedAt":"2026-09-12T03:13:01.744Z","slug":"CVE-2025-68939","body":"## Overview\n\nGitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.\n\n## Affected packages\n\n- `code.gitea.io/gitea`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":45.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}