9.5
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Description
Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of mishandling of out-of-repository symlink destinations for template repositories. This is also fixed for 11 LTS in 11.0.7 and later.
AI Analysis
Mishandling of out-of-repository symlink destinations for template repositories allows attackers to write to unintended files, and possibly obtain server shell access.
Basic Information
ID
CVE-2025-68937
Source
mitre
Published
Dec 25, 2025 at 23:57
Modified
Dec 26, 2025 at 00:16
Affected Product
Vendor
Forgejo
Product
Forgejo
Version
12.0.0
Affected Versions
Forgejo Forgejo 12.0.0
Forgejo Forgejo 0
Forgejo Forgejo 0
CWE Classification
AI Assessment
AI Score
9.5 / 10
AI Severity
Critical
Vendor
Forgejo
Product
Forgejo
Version
12.0.0, before 13.0.2, 11 LTS before 11.0.7
References
- codeberg.org /forgejo/forgejo/src/branch/forgejo/release-notes-published/13.0.2.md
- codeberg.org /forgejo/forgejo/src/branch/forgejo/release-notes-published/11.0.7.md
- codeberg.org /forgejo/forgejo/milestone/29156
- codeberg.org /forgejo/forgejo/milestone/27340
- codeberg.org /forgejo/security-announcements/issues/43