Back to search
CVE-2025-68937
Published: Dec 25, 2025
Modified: Dec 26, 2025
PUBLISHED
Description
Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of mishandling of out-of-repository symlink destinations for template repositories. This is also fixed for 11 LTS in 11.0.7 and later.
| Vendor | Product | Versions |
|---|---|---|
Forgejo | Forgejo | affected 12.0.0 - < 13.0.2affected 0 - < 11.0.7 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now