PT-2026-55607 · Gitea · Gitea
CVSS v3.1
7.1
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Gitea versions prior to 1.26.3
Description
Git LFS (Large File Storage) object reuse allows users with repository access to authorize private source objects even if they lack Code-unit access.
Recommendations
Update Gitea to version 1.26.3 or later.
Exploit
Fix
IDOR
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitea