Description
Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release assets, allowing specially crafted names to affect dump output paths.
Related CPE's
Could not find any relations
References
Weaknesses
88ee5874-cf24-4952-aea0-31affedb7ff2
Secondary
CWE-22
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
5.3 · Medium
Information
Source identifier
88ee5874-cf24-4952-aea0-31affedb7ff2
Vulnerability status
Deferred
Published
2026-07-03T21:16:59.683Z
3 months agoLast modified
2026-07-07T18:16:38.090Z
3 months ago