Executive brief
Gitea's release asset export feature uses user-supplied release tag names and asset filenames to construct filesystem paths, allowing an attacker to create releases with specially crafted names (containing path traversal sequences) to write asset dumps outside the intended directory. An attacker with the ability to create releases could exploit this to overwrite or access files on the server.
Technical details
The vulnerability is a path traversal (CWE-22) in Gitea's repository dump functionality. When exporting release assets, the code directly incorporates release tag names and asset filenames into filesystem paths via filepath.Join() without sanitization. An attacker who can create releases with names containing path traversal sequences (e.g., "../../../tmp/malicious") can cause asset dumps to be written outside the restricted "release_assets" directory. The attack requires the ability to create releases in a repository but does not require admin privileges or user interaction. The fix, implemented in version 1.25.5, replaces user-controlled tag/asset names with UUIDs when constructing dump paths, eliminating the traversal vector. Patches are available in commits 833304a and f7ac507.
Affected products
- Gitea Gitea < 1.25.5
Timeline
- 2026-07-03: disclosed: CVE-2026-28705 and advisory GHSA-7jvx-g65v-r899 published
- 2026-03-16: patched: Gitea 1.25.5 released with fix
- 2026-03-05: other: Fix merged into main branch via PR #36799
- 2026-03-06: other: Fix backported to release/v1.25 branch via PR #36839