CVE-2025-68946 Overview
CVE-2025-68946 is a stored cross-site scripting (XSS) vulnerability in Gitea, the self-hosted Git service written in Go. The flaw exists in Gitea versions prior to 1.20.1. Attackers can supply a forbidden URL scheme such as javascript: when creating a link, bypassing input sanitization checks. When another user clicks the crafted link, the embedded script executes in their browser session under the Gitea origin. The vulnerability is categorized as [CWE-79] Improper Neutralization of Input During Web Page Generation.
Critical Impact
Authenticated attackers can inject javascript: URLs into Gitea content, leading to script execution in victim browsers, session compromise, and unauthorized repository actions performed as the victim user.
Affected Products
- Gitea versions prior to 1.20.1
- Self-hosted Gitea Git service instances
- Gitea deployments that permit user-generated links in repositories, issues, or comments
Discovery Timeline
- 2025-12-26 - CVE-2025-68946 published to the National Vulnerability Database (NVD)
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-68946
Vulnerability Analysis
Gitea renders user-supplied links across many surfaces including issue bodies, pull request descriptions, comments, wiki pages, and Markdown-rendered README files. The link handling logic maintains a deny-list of URL schemes considered dangerous, such as javascript:, data:, and vbscript:. Prior to version 1.20.1, the deny-list check could be circumvented, allowing a forbidden scheme to reach the rendered HTML output as an active href attribute.
When a victim clicks the resulting anchor, the browser evaluates the scheme handler and executes attacker-controlled JavaScript in the context of the Gitea origin. The script inherits the victim's authenticated session and can perform any action the user is authorized to perform, including reading private repositories, modifying code, and creating or revoking API tokens.
Root Cause
The root cause is incomplete input sanitization of the URL scheme component in Gitea's link normalization routine. The scheme validator did not properly canonicalize input before comparing it against the forbidden list, allowing crafted variants of javascript: to slip through. The fix in Gitea Pull Request #25960 tightens scheme validation before the link is written to the DOM.
Attack Vector
Exploitation requires an authenticated user with permission to submit content, and social interaction from a victim who clicks the malicious link. The attacker creates content such as an issue, comment, or Markdown file containing a link whose scheme resolves to javascript: after Gitea's flawed normalization. When any user with access to that content clicks the link, JavaScript executes under the Gitea origin. Because Gitea instances typically host multiple projects and administrators, a single crafted link can target privileged accounts and pivot to repository takeover.
See the Gitea Release Announcement 1.20.1 for the vendor's summary of the security fix.
Detection Methods for CVE-2025-68946
Indicators of Compromise
- Anchor tags rendered in issues, comments, wikis, or Markdown pages containing href values that begin with javascript:, data:, or other non-HTTP schemes.
- Outbound requests from user browsers to attacker-controlled endpoints immediately after a user views a Gitea page.
- Unexpected creation, modification, or deletion of API tokens, SSH keys, or webhooks tied to legitimate user accounts.
Detection Strategies
- Query the Gitea database for stored content containing the string javascript: inside Markdown link constructs across issue, comment, and wiki tables.
- Enable and monitor Content Security Policy (CSP) violation reports for script-src and inline-script violations originating from the Gitea domain.
- Correlate Gitea audit log entries for token creation and permission changes with prior page views to identify session-riding activity.
Monitoring Recommendations
- Log and review all user-submitted Markdown content for anchor elements whose scheme is not http, https, mailto, or ftp.
- Monitor authenticated Gitea sessions for anomalous API activity such as rapid token issuance, repository visibility changes, or webhook additions.
- Alert on Gitea version banners exposing releases older than 1.20.1 in periodic asset inventory scans.
How to Mitigate CVE-2025-68946
Immediate Actions Required
- Upgrade all Gitea instances to version 1.20.1 or later using the official binaries listed in the Gitea 1.20.1 Release Notes.
- Rotate user API tokens, OAuth applications, and SSH deploy keys if the instance was exposed to untrusted contributors before patching.
- Audit recently modified issues, pull requests, wiki pages, and comments for links using non-standard URL schemes and remove them.
Patch Information
The fix is delivered in Gitea 1.20.1 via Gitea Pull Request #25960. The patch enforces stricter URL scheme validation during Markdown rendering and rejects links whose normalized scheme is not on the allow-list. Container users should pull the gitea/gitea:1.20.1 image or later. Binary installs should replace the gitea executable and restart the service.
Workarounds
- Deploy a Content Security Policy that blocks inline script execution and restricts script-src to trusted origins, reducing XSS impact until patching completes.
- Restrict repository and issue creation to trusted users on public-facing Gitea instances to limit the attacker population.
- Place Gitea behind a web application firewall (WAF) rule that inspects rendered HTML responses for href="javascript: patterns and blocks them.
# Upgrade Gitea to patched version 1.20.1 or later
systemctl stop gitea
wget https://github.com/go-gitea/gitea/releases/download/v1.20.1/gitea-1.20.1-linux-amd64 -O /usr/local/bin/gitea
chmod +x /usr/local/bin/gitea
systemctl start gitea
gitea --version
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.