MEDIUM 5.4 Go

Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text

GHSA-898p-hh3p-hf9r · BIT-gitea-2025-68942 · CVE-2025-68942 · GO-2025-4263

Published · Modified

Description

Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text.

Ready to move

Start Securing

Free, no credit card | First findings in minutes