Back

MEDIUM

gitea: Gitea: Cross-Site Scripting (XSS) vulnerability via search input

Published Dec 26, 2025

Description

Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text.

Affected products

Remediation

Red Hat statement

This vulnerability is rated Moderate for Red Hat OpenShift Pipelines versions 1.16 and 1.17 due to a Cross-Site Scripting (XSS) flaw in the integrated Gitea component. The flaw allows a remote attacker to inject malicious scripts via the search input, potentially leading to information disclosure or unauthorized actions in the context of the user's browser. OpenShift Pipelines versions 1.18, 1.19, and 1.20 are not affected as the vulnerable code is not present.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 26, 2025
Updated Dec 26, 2025
Reserved Dec 26, 2025
CISA Vulnrichment
Updated Dec 26, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 26, 2025
GHSA-898P-HH3P-HF9R