All verified exploits

CVE-2025-68937 Forgejo Template Repo Symlink RCE

Pentest critical Forgejo Added cve-verified-cve-2025-68937

Detects Forgejo instances before 13.0.2 (and Gitea <= 1.24.6) vulnerable to arbitrary file read/write via symlink following in template repository expansion. An authenticated attacker creates a template repository with a symbolic link pointing outside the repo, and when a new repository is generated from it, the template engine follows the symlink — reading and writing to arbitrary files on the server. Combined with SSH authorized_keys injection, this leads to full remote code execution.

Is your app exploitable through CVE-2025-68937?

Scan your domain free