Unrated severityNVD Advisory· Published Jul 3, 2026· Updated Jul 7, 2026
Gitea template repository generation mishandles symlinked paths
CVE-2026-25718
Description
Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processing to read or write through symlinked or otherwise non-regular paths.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/go-gitea/gitea/pull/36734mitrepatch
- github.com/go-gitea/gitea/pull/36746mitrepatch
- blog.gitea.com/release-of-1.25.5/mitrerelease-notes
- github.com/go-gitea/gitea/releases/tag/v1.25.5mitrerelease-notes
News mentions
0No linked articles in our index yet.