A AegiFlow
MEDIUMCVSS 5.3EPSS 0.5%

CVE-2026-28705

Gitea release asset dumps permit path traversal through crafted names

Published
2026-07-03
Modified
2026-09-01
EPSS percentile
38%
Aliases
GHSA-7jvx-g65v-r899
Sources
github-advisory

Summary

Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release assets, allowing specially crafted names to affect dump output paths.

Affected packages

EcosystemPackageAffected versionsFixed versions
Gocode.gitea.io/gitea1.25.5

Remediation: Upgrade to 1.25.5 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.