Multiple critical vulnerabilities in the open-source Gitea platform, including security bypass, information disclosure, cross-site scripting, and file manipulation flaws, can be exploited by a remote attacker. The CVSS Base Score is 9.0 (Critical). Affected versions include all releases prior to version 1.25.2, and users must upgrade to Gitea 1.25.2 to mitigate the threat.
[WID-SEC-2025-2925] Gitea: Mehrere Schwachstellen CVSS Base Score 9.0 (kritisch) CVSS Temporal Score 7.8 (hoch) Remoteangriff ja Datum 28.12.2025 Stand UPDATE 06.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux Sonstiges UNIX Windows Produktbeschreibung Gitea ist ein quelloffener Github-Klon. Produkte 28.12.2025 Open Source Gitea <1.25.2 Angriff Angriff Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um einen Cross-Site Scripting Angriff durchzufĂĽhren, und um Dateien zu manipulieren. CVE Informationen Versionshistorie Feedback zum Advisory geben