Summary
CVE-2026-25718 is a critical symlink-following path traversal vulnerability (CWE-59) in Gitea Open Source Git Server, affecting all versions prior to 1.25.5. The flaw resides in the template repository generation workflow, where path resolution fails to reject symlinked or non-regular filesystem paths, allowing an attacker to read or write arbitrary files on the underlying host — including injecting SSH keys to achieve remote code execution (RCE) as the git system user. With a CVSS 3.1 score of 9.1 (Critical) and a public proof-of-concept exploit available, unpatched internet-exposed Gitea instances are at immediate and material risk.
Technical details
- Root cause: During template repository generation, Gitea’s path resolution logic (CWE-59: Improper Link Resolution Before File Access / ‘Link Following’) does not validate whether file paths resolve through symbolic links or to non-regular filesystem objects. The template engine operates on the dereferenced target rather than the intended repository content.
- Trigger conditions: An attacker creates a malicious template repository containing a symlink targeting a sensitive file (e.g., the
gituser’s~/.ssh/authorized_keys). A template variable such as${REPO_DESCRIPTION}is embedded in the symlinked file’s content. When a new repository is created from this template with Git content templating enabled, the engine expands the variable using the attacker-controlled repository description — effectively writing an arbitrary string into the symlink target. - Attack vector: Network — exploitable entirely remotely. The public PoC demonstrates exploitation by a registered user account; on Gitea instances with open user registration (a common default for self-hosted community deployments), no elevated privileges are required to obtain an account and trigger the vulnerability.
- Impact:
- Arbitrary file write — injection of an attacker-controlled SSH public key into
authorized_keys, granting interactive shell login as thegitsystem user (full RCE). - Arbitrary file read — access to sensitive server-side files via the symlink dereference path.
- Secondary impacts — corruption of Gitea configuration files, SQLite database manipulation, or denial of service through forced access to large files.
- Arbitrary file write — injection of an attacker-controlled SSH public key into
Affected software
- Gitea Open Source Git Server: all versions before 1.25.5
Severity
CVSS v3.1 Base Score: 9.1 (Critical)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: Upgrade to Gitea 1.25.5 or later. The fix was introduced via pull requests #36734 and #36746, correcting path resolution handling during template repository generation.
- If immediate patching is not feasible:
- Restrict network access to the Gitea web interface using firewall rules or a reverse proxy with IP allowlisting.
- Disable open/public user registration to prevent unauthenticated actors from obtaining accounts.
- Disable or restrict the use of template repositories until patching is complete.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

