CVE-2025-68945: Medium severity gitea vulnerability
Published Dec 26, 2025
·Updated
In Gitea before 1.21.2, an anonymous user can visit a private user's project.
Affected Software
3 affected componentsFixes available
gitea<1.21.2
go/code.gitea.io/gitea<1.21.2
1.21.2
Gitea Gitea<1.21.2
Remediation
Patch Available
Event History
Dec 26, 2025
CVE Published
via MITRE·03:58 AM
Data Sourced
via MITRE·03:58 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·06:30 AM
Data Sourced
via GitHub·06:30 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-68945?
CVE-2025-68945 is considered a medium severity vulnerability due to its potential impact on user privacy.
2
How do I fix CVE-2025-68945?
To fix CVE-2025-68945, upgrade Gitea to version 1.21.2 or later.
3
Who is affected by CVE-2025-68945?
CVE-2025-68945 affects Gitea installations prior to version 1.21.2, allowing anonymous users access to private projects.
4
What type of vulnerability is CVE-2025-68945?
CVE-2025-68945 is an access control vulnerability that permits unauthorized access to private user projects.
5
When was CVE-2025-68945 disclosed?
CVE-2025-68945 was disclosed in conjunction with the release of Gitea version 1.21.2.