We found results for “”
CVE-2025-68937
Good to know:
Date: December 25, 2025
Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of mishandling of out-of-repository symlink destinations for template repositories. This is also fixed for 11 LTS in 11.0.7 and later.
Severity Score
Related Resources (8)
Severity Score
Weakness Type (CWE)
UNIX Symbolic Link (Symlink) Following
CWE-61Top Fix
Upgrade Version
Upgrade to version https://codeberg.org/forgejo/forgejo.git - v13.0.2;https://codeberg.org/forgejo/forgejo.git - v11.0.7
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | HIGH |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | CHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


