blob: abf5051295461652a6d19810996348dbcba4654e [file]
id: GO-2025-4265
modules:
- module: code.gitea.io/gitea
versions:
- fixed: 1.20.1
vulnerable_at: 1.20.0
summary: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
cves:
- CVE-2025-68946
ghsas:
- GHSA-hq57-c72x-4774
references:
- advisory: https://github.com/advisories/GHSA-hq57-c72x-4774
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-68946
- web: https://blog.gitea.com/release-of-1.20.1
- web: https://github.com/go-gitea/gitea/pull/25960
- web: https://github.com/go-gitea/gitea/releases/tag/v1.20.1
source:
id: GHSA-hq57-c72x-4774
created: 2025-12-29T19:19:01.917879328Z
review_status: UNREVIEWED