CVE-2025-68939 | Gitea up to 1.22.x Attachment API improper protection of alternate path (EUVD-2025-205411)
A vulnerability was found in Gitea up to 1.22.x. It has been classified as problematic. This issue affects some unknown processing of the component Attachment API. The manipulation leads to improper protection of alternate path.
This vulnerability is documented as CVE-2025-68939. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.