URL has been copied successfully!
Critical Gitea Flaw Lets Public-Only Tokens Write to Private Repositories and Trigger Actions Workflows
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Critical Gitea Flaw Lets Public-Only Tokens Write to Private Repositories and Trigger Actions Workflows

Gitea administrators are strongly encouraged to upgrade their systems following the discovery of a critical authorization vulnerability. This flaw allows public-only API tokens to modify private pull request branches and potentially trigger Gitea Actions workflows. The vulnerability, tracked as CVE-2026-58443 and GHSA-xxjv-752h-3vp2, affects Gitea versions up to and including 1.26.4. The issue has been resolved […] The post Critical Gitea Flaw Lets Public-Only Tokens Write to Private Repositories and Trigger Actions Workflows appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

First seen on gbhackers.com

Jump to article: gbhackers.com/critical-gitea-flaw-trigger-actions-workflows/

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link