Vulnerability in Gitea's Push Mirror API Could Allow Unauthorized Local Path Access
CVE-2026-86684
Currently unrated
What is CVE-2026-86684?
The Gitea push mirror API has a flaw that allows repository administrators, who do not have the permission to import local paths, to potentially exploit the system. When the configuration setting [security] IMPORT_LOCAL_PATHS is enabled, an administrator could set a push mirror to a local path on the server. This action allows the repository administrator to push repository references into an existing Git repository located at that path, using the privileges assigned to the Gitea process. This vulnerability raises concerns about unauthorized access to file paths, compromising the integrity of the repository and the security of the underlying server.
Affected Version(s)
Gitea 1.18.0 <= 28.0.0
