CVE-2025-68937: Critical severity forgejo/forgejo vulnerability
Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of mishandling of out-of-repository symlink destinations for template repositories. This is also fixed for 11 LTS in 11.0.7 and later.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68937?
CVE-2025-68937 is considered a high severity vulnerability due to its potential to allow attackers to gain server shell access.
How do I fix CVE-2025-68937?
To fix CVE-2025-68937, upgrade Forgejo to version 13.0.2 or later, or to version 11.0.7 or later for LTS.
What versions of Forgejo are affected by CVE-2025-68937?
CVE-2025-68937 affects Forgejo versions prior to 13.0.2 and 11.0.7.
What kind of attack does CVE-2025-68937 enable?
CVE-2025-68937 enables attackers to write to unintended files, potentially leading to unauthorized server access.
Is there any workaround for CVE-2025-68937 if I cannot upgrade immediately?
There are no documented workarounds for CVE-2025-68937, so it is recommended to upgrade to a patched version as soon as possible.