Vulnerability in Gitea's Push Mirror API Could Allow Unauthorized Local Path Access
CVE-2026-86684

Currently unrated

Key Information:

Vendor

Gitea

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-86684?

The Gitea push mirror API has a flaw that allows repository administrators, who do not have the permission to import local paths, to potentially exploit the system. When the configuration setting [security] IMPORT_LOCAL_PATHS is enabled, an administrator could set a push mirror to a local path on the server. This action allows the repository administrator to push repository references into an existing Git repository located at that path, using the privileges assigned to the Gitea process. This vulnerability raises concerns about unauthorized access to file paths, compromising the integrity of the repository and the security of the underlying server.

Affected Version(s)

Gitea 1.18.0 <= 28.0.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

https://github.com/opensec-intelligence
https://github.com/mayank-jangid-moon
https://github.com/Kushalkhemka
https://github.com/skigeek16
https://github.com/silverwind
https://github.com/bircni
.