PT-2026-55595 · Gitea · Gitea

·

CVE-2026-25782

·

Published

2026-07-03

·

Updated

2026-09-10

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Gitea versions prior to 1.25.5
Description The software fails to scope the lookup of tracked-time entries to the specific issue provided in the request URL when searching by time ID. This flaw allows an attacker to attempt the deletion of time entries associated with a different issue than the one specified in the request.
Recommendations Update Gitea to version 1.25.5 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25782
GHSA-QM72-8PRH-G92X
GO-2026-6343

Affected Products

Gitea