Critical Gitea Flaw Lets Public-Only Tokens Write to Private Repositories and Trigger Actions Workflows
ID: 383cf59e-d75b-533b-ab66-ad8d09711112
STIX ID: report--383cf59e-d75b-533b-ab66-ad8d09711112
Feed Name: GBHackers
Threat Score
Gitea has a critical CWE-863 authorization flaw (CVE-2026-58443) in which public-only API tokens can be used to update private pull request head branches via the public pull request update endpoint, potentially triggering private Actions workflows; the issue (CVSS 3.1 = 10.0) affects versions up to 1.26.4 and is fixed in 1.27.0, and administrators are advised to upgrade immediately and audit tokens, PR update API activity, and private Actions runs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
