logo

Critical Gitea Flaw Lets Public-Only Tokens Write to Private Repositories and Trigger Actions Workflows

ID: 383cf59e-d75b-533b-ab66-ad8d09711112

STIX ID: report--383cf59e-d75b-533b-ab66-ad8d09711112

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Divya

...
...

Gitea has a critical CWE-863 authorization flaw (CVE-2026-58443) in which public-only API tokens can be used to update private pull request head branches via the public pull request update endpoint, potentially triggering private Actions workflows; the issue (CVSS 3.1 = 10.0) affects versions up to 1.26.4 and is fixed in 1.27.0, and administrators are advised to upgrade immediately and audit tokens, PR update API activity, and private Actions runs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.