CRITICAL🇵🇱 Wersja polska

CVE-2026-20912

CVSS 9.1v3.1pub. 2026-01-22upd. 2026-06-27

Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users.

🤖 AI Analysis
How it works

The vulnerability consists of lack of proper validation of attachment ownership to a repository during the operation of linking it to a release. An attacker can upload an attachment to a private repository and then link it to a release in another public repository. As a result, a file originally restricted to a private repository becomes accessible to all users with access to the public repository.

Impact

An attacker can gain unauthorized access to confidential files stored in private repositories and manipulate their associations with releases in other repositories, leading to violations of data confidentiality and integrity.

Mitigation & patch

Gitea should be updated to version v1.25.4 or newer, which contains fixes described in pull requests #36320 and #36355. Details available at: https://blog.gitea.com/release-of-1.25.4/

Who is affected

Gitea — versions indicated in producer references (patches available in version v1.25.4)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Gitea

    APP
    Gitea
    < 1.25.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-60004CRITICAL9.8⚠ KEVsame product

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

CVE-2026-20750CRITICAL9.1PL ✓same product

Gitea: nieprawidłowa walidacja własności projektów organizacji

CVE-2026-20897CRITICAL9.1PL ✓same product

Gitea: nieautoryzowane usuwanie blokad Git LFS między repozytoriami

CVE-2022-42968CRITICAL9.8PL ✓same product

Gitea: brak sanityzacji refs prowadzący do wstrzyknięcia argumentów git

CVE-2021-45330CRITICAL9.8PL ✓same product

Gitea: nieprawidłowe unieważnianie sesji umożliwia przejęcie uprawnień