Impact
Gitea’s migration restore routine accepts a file:// URI, allowing a local file inclusion (CWE‑284). This flaw can enable an attacker to read arbitrary files on the host or, if an inclusion endpoint is exploitable, execute arbitrary code. The impact is a compromise of confidentiality, integrity and possibly availability of the affected instance.
Affected Systems
The vulnerability is present in Gitea Open Source Git Server, though specific affected versions are not listed in the data. It applies to installations that expose the migration restore functionality.
Risk and Exploitability
The CVE has no EPSS score listed and is not in the CISA KEV catalog, implying limited publicly known exploitation. The attack vector is that an authenticated user with migration privileges can supply a file:// URI; thus the exploitation likelihood depends on who can access the feature. The absence of an explicit CVSS score means the technical severity cannot be quantified here, but local file inclusion is generally regarded as a high‑risk weakness.
OpenCVE Enrichment
Github GHSA