Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 26 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 26 Dec 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | forgejo: Forgejo: Server shell access via symlink mishandling in template repositories | |
| Weaknesses | CWE-59 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Fri, 26 Dec 2025 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 26 Dec 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Forgejo
Forgejo forgejo |
|
| CPEs | cpe:2.3:a:forgejo:forgejo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Forgejo
Forgejo forgejo |
|
| Metrics |
cvssV4_0
|
Fri, 26 Dec 2025 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of mishandling of out-of-repository symlink destinations for template repositories. This is also fixed for 11 LTS in 11.0.7 and later. | |
| Weaknesses | CWE-61 | |
| References |
|
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-26T14:51:12.778Z
Reserved: 2025-12-25T23:57:30.203Z
Link: CVE-2025-68937
Updated: 2025-12-26T14:40:09.634Z
Status : Deferred
Published: 2025-12-26T00:16:01.173
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-68937
OpenCVE Enrichment
No data.