CVE-2025-68941
Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public res
Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.
MEDIUM · CVSS 4.9
EPSS 9e-05
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0