logo

Critical Gitea Vulnerability Enables Private Repository Writes and Actions Workflow Triggers

ID: 70077cc2-9c46-5e85-be8f-b06697383940

STIX ID: report--70077cc2-9c46-5e85-be8f-b06697383940

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Abinaya

...
...

A critical Gitea vulnerability (CVE-2026-58443, CVSS 9.6) in the pull request update API lets a public-only repository token with write scope be used to push commits from a public base repository into a private pull request head branch, bypassing the token's public-only restriction and potentially triggering private Actions workflows. Administrators are urged to upgrade to v1.27.0 and review tokens, pull-request update permissions, and Actions logs to mitigate exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.