logo

Critical Gitea Vulnerability Lets Public Repository Tokens Trigger Private Workflows

ID: 60e12023-e569-534c-9519-2127b6a2e89e

STIX ID: report--60e12023-e569-534c-9519-2127b6a2e89e

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Tamilselvan

...
...

A critical authorization vulnerability (CVE-2026-58443) in Gitea's pull request update endpoint allows public-only API tokens to cause server-side pushes into private head repositories and therefore trigger private Actions workflows. The PoC shows a public-scoped token can merge public commits into a private branch and fire private CI; affected versions up to v1.26.4 are patched in v1.27.0, and operators are advised to upgrade, audit public-only tokens, and review private Actions logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.