CVE-2026-96594 | Gitea up to 28.0.0 Media {filepath} cross site scripting
A vulnerability was found in Gitea up to 28.0.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /api/v1/repos/{owner}/{repo}/media/{filepath} of the component Media. The manipulation results in cross site scripting.
This vulnerability is known as CVE-2026-96594. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More