CVE-2026-26231
Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write.
Fraqueza
Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write.
Referências
- https://blog.gitea.com/release-of-1.26.2/
- https://github.com/go-gitea/gitea/pull/37479
- https://github.com/go-gitea/gitea/pull/37484
- https://github.com/go-gitea/gitea/releases/tag/v1.26.2
- https://github.com/go-gitea/gitea/security/advisories/GHSA-mm7c-rhg6-qr4r
- https://github.com/go-gitea/gitea/security/advisories/GHSA-mm7c-rhg6-qr4r
Encontre a falha antes de um atacante.
Entre com o GitHub e rode sua primeira auditoria em menos de um minuto. O plano gratuito não exige cartão de crédito.