Gitea API Vulnerability Exposes User Sessions via Improper File Handling
CVE-2026-96594
Currently unrated
What is CVE-2026-96594?
A vulnerability in Gitea's API endpoint allows an attacker to expose user sessions by returning files without appropriate content type and disposition headers. As a result, browsers can render files inappropriately, enabling JavaScript execution within the context of a user's session. Users with push access to a repository could exploit this flaw, jeopardizing the security of those who interact with the media URL. Prompt awareness and remediation are crucial to mitigate potential risks.
Affected Version(s)
Gitea 0 <= 28.0.0
