# Gitea 1.24.7 is released

DevFeed: [Gitea 1.24.7 is released](<https://devfeed.tech/articles/gitea-1-24-7-is-released-54935.md>)

Original publisher: [Read original article](<https://blog.gitea.com/release-of-1.24.7/>)

Author: lunny

Published: 2025-10-26T04:04:00Z

Content type: release

Language: en

Sources: [Gitea Blog](<https://devfeed.tech/sources/gitea-blog.md>)

Topics: [Gitea](<https://devfeed.tech/topics/gitea.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [JSON Web Tokens](<https://devfeed.tech/topics/jwt.md>), [OAuth 2.0](<https://devfeed.tech/topics/oauth2.md>), [Repository](<https://devfeed.tech/topics/repository.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [gitea](<https://devfeed.tech/tags/gitea.md>), [jwt](<https://devfeed.tech/tags/jwt.md>), [oauth2](<https://devfeed.tech/tags/oauth2.md>), [release](<https://devfeed.tech/tags/release.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>), [version](<https://devfeed.tech/tags/version.md>)

## AI overview

Gitea 1.24.7 is a maintenance release that recommends upgrading for stability and security. It includes seven merged pull requests and addresses vulnerabilities involving LFS authentication bypass, arbitrary file access through malicious template repositories, and invalidated OAuth2 tokens being accepted.

## Source excerpt

We are excited to announce the release of **Gitea version 1.24.7**! We strongly recommend all users upgrade to this version for improved stability and security. This release includes [7 merged pull requests](https://github.com/go-gitea/gitea/pulls?q=is%3Apr+milestone%3A1.24.7+is%3Amerged), thanks to the amazing contributions from our community. ## Security This release addresses several important security vulnerabilities: - LFS Authentication Bypass A user without valid credentials could upload or download LFS files by submitting a malformed JWT token. Thanks to Scott Tolley from Black Duck for reporting this issue, and to @wxiaoguang for the fix in https://github.com/go-gitea/gitea/pull/35708. - Arbitrary File Access via Malicious Template Repositories An authenticated user could create a crafted template repository that processes arbitrary files on the filesystem. Thanks to [Clément Hamada](https://github.com/ClemaX) for reporting this issue, and to @wxiaoguang for the fix in https://github.com/go-gitea/gitea/pull/35708. - Invalidated OAuth2 Tokens Still Accepted An invalidated OAuth2 token could incorrectly pass validation. Thanks to TIA for reporting this issue, and to @lunny for the fix in https://github.com/go-gitea/gitea/pull/35655. ## How to install or update Download our pre-built binaries from the [Gitea downloads page](https://dl.gitea.com/gitea/1.24.7/) -- make sure to select the version compatible with your platform. For a step-by-step guide on installation or upgrades, check out our [installation documentation](https://docs.gitea.com/category/installation) ## Special Thanks We would also like to thank all of our supporters on [Open Collective](https://opencollective.com/gitea) who are helping to sustain us financially. --- Looking for a seamless, hassle-free solution to manage your Git repositories? Discover [Gitea Cloud](https://cloud.gitea.com) -- A fully-managed, scalable platform designed to streamline your development workflow.