gitea: Gitea: Cross-Site Scripting (XSS) vulnerability via search input
Published Dec 26, 2025
5.4
MEDIUMCVSS 3.1
EPSS 0.25%
Description
Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text.
Affected products
-
- Version 0StatusaffectedConstraints<1.22.2
- Version
No data.
OpenShift Pipelines
openshift-pipelines/pipelines-pipelines-as-code-cli-rhel8
Out of support scope
OpenShift Pipelines
openshift-pipelines/pipelines-pipelines-as-code-cli-rhel9
Not affected
OpenShift Pipelines
openshift-pipelines/pipelines-pipelines-as-code-controller-rhel8
Out of support scope
OpenShift Pipelines
openshift-pipelines/pipelines-pipelines-as-code-controller-rhel9
Not affected
OpenShift Pipelines
openshift-pipelines/pipelines-pipelines-as-code-watcher-rhel8
Out of support scope
OpenShift Pipelines
openshift-pipelines/pipelines-pipelines-as-code-watcher-rhel9
Not affected
OpenShift Pipelines
openshift-pipelines/pipelines-pipelines-as-code-webhook-rhel8
Out of support scope
OpenShift Pipelines
openshift-pipelines/pipelines-pipelines-as-code-webhook-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-cli-rhel8 | Out of support scope | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-cli-rhel9 | Not affected | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-controller-rhel8 | Out of support scope | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-controller-rhel9 | Not affected | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-watcher-rhel8 | Out of support scope | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-watcher-rhel9 | Not affected | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-webhook-rhel8 | Out of support scope | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-pipelines-as-code-webhook-rhel9 | Not affected | n/a |
code.gitea.io/gitea
Go
Introduced 0 Fixed 1.22.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | code.gitea.io/gitea | 0 | 1.22.2 |
Remediation
Red Hat statement
This vulnerability is rated Moderate for Red Hat OpenShift Pipelines versions 1.16 and 1.17 due to a Cross-Site Scripting (XSS) flaw in the integrated Gitea component. The flaw allows a remote attacker to inject malicious scripts via the search input, potentially leading to information disclosure or unauthorized actions in the context of the user's browser. OpenShift Pipelines versions 1.18, 1.19, and 1.20 are not affected as the vulnerable code is not present.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Dec 26, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.25% (0.00247) | 14.56th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.22% (0.00222) | 12.56th | v5 (v2026.06.15) |
| Dec 26, 2025 | 0.03% (0.00029) | 7.57th | v4 (v2025.03.14) |
References (8)
- https://access.redhat.com/security/cve/CVE-2025-68942 Vendor Advisory
- https://blog.gitea.com/release-of-1.22.2 Release Notes
- https://bugzilla.redhat.com/show_bug.cgi?id=2425464 Issue Tracking
- https://github.com/advisories/GHSA-898p-hh3p-hf9r Advisory
- https://github.com/go-gitea/gitea/pull/31966 Issue TrackingPatch
- https://github.com/go-gitea/gitea/releases/tag/v1.22.2 Release Notes
- https://nvd.nist.gov/vuln/detail/CVE-2025-68942
- https://www.cve.org/CVERecord?id=CVE-2025-68942
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-68942 | Vendor Advisory | |
| https://blog.gitea.com/release-of-1.22.2 | Release Notes | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2425464 | Issue Tracking | |
| https://github.com/advisories/GHSA-898p-hh3p-hf9r | Advisory | |
| https://github.com/go-gitea/gitea/pull/31966 | Issue TrackingPatch | |
| https://github.com/go-gitea/gitea/releases/tag/v1.22.2 | Release Notes | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-68942 | ||
| https://www.cve.org/CVERecord?id=CVE-2025-68942 |
Change history (0)
No recorded changes yet.