CVE Database
/

CVE-2025-68937

Back to search

CVE-2025-68937

Published: Dec 25, 2025

Modified: Dec 26, 2025

PUBLISHED

Description

Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of mishandling of out-of-repository symlink destinations for template repositories. This is also fixed for 11 LTS in 11.0.7 and later.

VendorProductVersions

Forgejo

Forgejo

affected
12.0.0 - < 13.0.2
affected
0 - < 11.0.7

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now