MEDIUM
Gitea repository dumps write release assets using unsafe path names
Published Jul 3, 2026
5.3
MEDIUMCVSS 3.1
EPSS 0.45%
Description
Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release assets, allowing specially crafted names to affect dump output paths.
Affected products
-
- Version 0StatusaffectedConstraints<1.25.5
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Gitea | Gitea Open Source Git Server | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
code.gitea.io/gitea
Go
Introduced 0 Fixed 1.25.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | code.gitea.io/gitea | 0 | 1.25.5 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- https://blog.gitea.com/release-of-1.25.5 release-notes
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41641 Advisory
- https://github.com/advisories/GHSA-7jvx-g65v-r899 Advisory
- https://github.com/go-gitea/gitea/commit/833304ac15bce17d0f03c4852af5f60c186f6a70
- https://github.com/go-gitea/gitea/commit/f7ac5076711af3a260f3f98b2c1f8c19b32f6d09
- https://github.com/go-gitea/gitea/pull/36799 patch
- https://github.com/go-gitea/gitea/pull/36839 patch
- https://github.com/go-gitea/gitea/releases/tag/v1.25.5 release-notes
- https://nvd.nist.gov/vuln/detail/CVE-2026-28705
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Gitea
Published Jul 3, 2026
Updated Jul 7, 2026
Reserved Mar 3, 2026
Link CVE-2026-28705
CISA Vulnrichment
Updated Jul 7, 2026
ENISA EUVD
EUVD-2026-41641 GHSA-7JVX-G65V-R899 Assigner Gitea
Published Jul 3, 2026
Updated Jul 7, 2026
Exploited since n/a
Link EUVD-2026-41641