Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-25718: Gitea template generation can access unintended files

CVE-2026-25718 CVE-2026-25718
Summary

Gitea versions before 1.25.5 can read or write files outside intended templates, potentially exposing sensitive data. This affects users who store templates in non-standard locations. To protect your data, update to version 1.25.5 or later.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
gitea gitea open source git server < 1.25.5
Original title
Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processing to read or write through symlinked or otherwise non-regular paths.
Original description
Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processing to read or write through symlinked or otherwise non-regular paths.
Vulnerability type
CWE-59 Link Following
Published: 3 Jul 2026 · Updated: 23 Jul 2026 · First seen: 3 Jul 2026