CVE-2025-68941: Medium severity gitea vulnerability
Published Dec 26, 2025
·Updated
Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.
Affected Software
3 affected componentsFixes available
gitea<1.22.3
go/code.gitea.io/gitea<1.22.3
1.22.3
Gitea Gitea<1.22.3
Remediation
Patch Available
Event History
Dec 26, 2025
CVE Published
via MITRE·02:31 AM
Data Sourced
via MITRE·02:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·03:30 AM
Data Sourced
via GitHub·03:30 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-68941?
CVE-2025-68941 has been assigned a medium severity rating due to the potential for unauthorized access to private resources.
2
How do I fix CVE-2025-68941?
To fix CVE-2025-68941, upgrade Gitea to version 1.22.3 or later immediately.
3
What does CVE-2025-68941 affect?
CVE-2025-68941 affects versions of Gitea prior to 1.22.3, specifically concerning access controls for API tokens.
4
Is CVE-2025-68941 a risk for all Gitea users?
Yes, CVE-2025-68941 poses a risk to all Gitea users operating versions below 1.22.3.
5
Are there any workarounds for CVE-2025-68941 before upgrading?
No specific workarounds are recommended for CVE-2025-68941; upgrading to the patched version is the only solution.