Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58416

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 6.5

Описание

Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)

A flaw was found in Gitea. The Fork-PR Actions task, which handles pull requests from forked repositories, can be exploited to read data from a third private repository. This occurs due to a missing guard that should prevent unauthorized access via the collaborative-owner branch. A remote attacker could leverage this vulnerability to gain unauthorized access to sensitive information.

Отчет

A flaw was found in Gitea's Actions continuous integration runner logic for pull requests from forked repositories. Due to a missing permission boundary check on collaborative-owner branches, a Gitea Actions workflow triggered by a fork pull request can access unauthorized repository contexts. An authenticated remote user with write access to a fork can exploit this vulnerability to read sensitive data and configuration secrets from a third private repository accessible to the collaborative owner.

Меры по смягчению последствий

To mitigate this issue, repository administrators should disable Gitea Actions on affected repositories or restrict pull request workflows from fork repositories by configuring RUN_WORKFLOWS_FROM_FORK_PULL_REQUESTS to false in the Gitea configuration.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-watcher-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1220
https://bugzilla.redhat.com/show_bug.cgi?id=2515475gitea.dev: Gitea: Information disclosure via Fork-PR Actions task

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.1
nvd
20 дней назад

Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)

redos
21 день назад

Уязвимость gitea

redos
21 день назад

Уязвимость gitea

CVSS3: 6.3
github
около 1 месяца назад

Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)

6.5 Medium

CVSS3

Уязвимость CVE-2026-58416