Security Advisory
CVE-2025-68946
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS.
CVE vulnerability detail — eXtreme Datacenter Security Operations
In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS.