CRITICAL🇵🇱 Wersja polska

CVE-2026-20750

CVSS 9.1v3.1pub. 2026-01-22upd. 2026-06-27

Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization.

🤖 AI Analysis
How it works

The vulnerability stems from improper access control (CWE-284) during operations on organizational projects. A user with write permissions in a project of one organization can send requests concerning projects belonging to another organization, as Gitea does not properly verify whether the given project actually belongs to the organization specified in the request. This allows bypassing isolation boundaries between organizations.

Impact

An attacker can unauthorized modify projects belonging to organizations for which they do not have permissions, violating data integrity and compromising the confidentiality of project configurations of other organizations.

Mitigation & patch

Update Gitea to version 1.25.4 or later. Patch available in vendor references: https://github.com/go-gitea/gitea/releases/tag/v1.25.4

Who is affected

Gitea — versions indicated in vendor references (vulnerability fixed in version 1.25.4)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Gitea

    APP
    Gitea
    < 1.25.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-60004CRITICAL9.8⚠ KEVsame product

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

CVE-2026-20897CRITICAL9.1PL ✓same product

Gitea: nieautoryzowane usuwanie blokad Git LFS między repozytoriami

CVE-2026-20912CRITICAL9.1PL ✓same product

Gitea: nieautoryzowany dostęp do załączników z prywatnych repozytoriów

CVE-2022-42968CRITICAL9.8PL ✓same product

Gitea: brak sanityzacji refs prowadzący do wstrzyknięcia argumentów git

CVE-2021-45330CRITICAL9.8PL ✓same product

Gitea: nieprawidłowe unieważnianie sesji umożliwia przejęcie uprawnień