Critical Gitea Vulnerability Enables Private Repository Writes and Actions Workflow Triggers

Gitea users are urged to update immediately after a critical vulnerability was disclosed that allows public-only repository access tokens to indirectly write to private pull request branches and trigger private Actions workflows. Tracked as CVE-2026-58443, the vulnerability affects Gitea versions up to v1.26.4 and has been fixed in v1.27.0. The flaw exists in Gitea’s pull […]

The post Critical Gitea Vulnerability Enables Private Repository Writes and Actions Workflow Triggers appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: