Critical Gitea Vulnerability Enables Private Repository Writes and Actions Workflow Triggers
ID: 70077cc2-9c46-5e85-be8f-b06697383940
STIX ID: report--70077cc2-9c46-5e85-be8f-b06697383940
Feed Name: cybersecurityNews.com
Threat Score
A critical Gitea vulnerability (CVE-2026-58443, CVSS 9.6) in the pull request update API lets a public-only repository token with write scope be used to push commits from a public base repository into a private pull request head branch, bypassing the token's public-only restriction and potentially triggering private Actions workflows. Administrators are urged to upgrade to v1.27.0 and review tokens, pull-request update permissions, and Actions logs to mitigate exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
