Gitea · Gitea · CVE-2026-28705
**Name of the Vulnerable Software and Affected Versions**
Gitea versions prior to 1.25.5
**Description**
The software uses release tag names and asset names as filesystem path components during the process of dumping release assets. This behavior allows specially crafted names to manipulate the resulting dump output paths.
**Recommendations**
Update Gitea to version 1.25.5 or later.