Gitea is an open-source self-hosted Git service. In versions prior to 1.25.5, the `dump-repo` CLI command is vulnerable to a path traversal attack allowing arbitrary file writes with attacker-controlled content.
Author: Robert
-
Gitea
-
CVE-2026-28705 ‒ Arbitrary File Write via Path Traversal in Gitea dump-repo Command
-
-
Taiga