Insufficient Permission Checks in Gitea by Gitea Team
CVE-2026-24690
7.5HIGH
What is CVE-2026-24690?
Gitea, a popular self-hosted Git service, is affected by insufficient permission checks in versions prior to 1.25.5. This vulnerability allows unauthorized users to update or rebase pull request branches, potentially compromising the integrity of the repository and the code submission process. The issue has been addressed in version 1.25.5, ensuring that proper permissions are enforced for such operations. Users are strongly advised to upgrade to the latest version to mitigate these risks and protect their projects.
Affected Version(s)
Gitea Open Source Git Server 0 < 1.25.5
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
the CodeThreat Security Research Team and Alexander Girgis
