Cross-Repository Issue in Gitea Exposes Private Attachment Content
CVE-2026-57886
Currently unrated
What is CVE-2026-57886?
A cross-repository issue in Gitea allows for improper re-linking of comments and attachments, which may expose private attachment content. This vulnerability arises when user-generated content in one repository is able to reference or link to attachments stored in another. As a result, users could unintentionally gain access to sensitive information that should remain protected within private repositories. It is essential for users to update to the latest version to mitigate this risk and ensure the integrity of their private data.
Affected Version(s)
Gitea Open Source Git Server 0 <= 1.26.4
