Critical Gitea Vulnerability Lets Public Repository Tokens Trigger Private Workflows
ID: 60e12023-e569-534c-9519-2127b6a2e89e
STIX ID: report--60e12023-e569-534c-9519-2127b6a2e89e
Feed Name: Cyber Press
A critical authorization vulnerability (CVE-2026-58443) in Gitea's pull request update endpoint allows public-only API tokens to cause server-side pushes into private head repositories and therefore trigger private Actions workflows. The PoC shows a public-scoped token can merge public commits into a private branch and fire private CI; affected versions up to v1.26.4 are patched in v1.27.0, and operators are advised to upgrade, audit public-only tokens, and review private Actions logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
