Executive brief
Gitea, a self-hosted Git service, contains a path traversal vulnerability in its template repository generation feature that allows an attacker to read or write files outside the intended directory through symlinks or crafted paths. An attacker without authentication can exploit this to access sensitive repository data or modify files on the server hosting Gitea.
Technical details
The vulnerability is a CWE-59 (Improper Link Resolution Before File Access / Link Following) flaw in Gitea's template repository generation logic. During path resolution, the code fails to properly validate or normalize paths, permitting symlinks and other non-regular filesystem paths to be traversed. An attacker can supply a crafted repository name or template path that resolves through symlinks to read arbitrary files or write to unintended locations on the server. The attack requires network access to Gitea's web interface and no authentication or user interaction; the vulnerability is triggered when creating or processing template repositories. The fix, included in Gitea 1.25.5, properly resolves and validates filesystem paths before access. References: GitHub PR #36734, #36746.
Affected products
- Gitea Gitea < 1.25.5
Timeline
- 2026-07-03: disclosed: Vulnerability published to GitHub Advisory Database
- 2026-03-16: patched: Fix released in Gitea 1.25.5