Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.2%top 90%

Gitea: Permanent Fork PR Workflow Approval Gate Bypass (CVE-2026-58424)

0
High
Published: 07/21/2026 (07/21/2026, 20:35:51 UTC)
Source: GCVE Database
Vendor/Project: Gitea
Product: code.gitea.io/gitea

Description

Gitea Actions contains a vulnerability in the fork pull request workflow approval gate that allows an attacker with a single unprivileged account and one-time maintainer approval on a benign fork PR to permanently bypass approval for all future fork PR workflow runs from that user on the same repository. This bypass occurs because the approval check only verifies if the user has any previously approved run in the repository, without considering the pull request, commit, or workflow contents. The vulnerability affects all Gitea versions from v1.20.0 onward and remains unpatched as of this disclosure.

CVSS v3.1

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H

Affected software

GitHub Actionsmore threats →ai
go-gitea/gitea
pkg:github/go-gitea/gitea
Affected versions
=0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/22/2026, 01:47:03 UTC

Technical Analysis

The vulnerability (CVE-2026-58424) resides in Gitea Actions' approval gate for workflows triggered by fork pull requests. The function ifNeedApproval incorrectly skips approval if the triggering user has any previously approved workflow run in the repository, regardless of the PR, commit, or workflow file. This logic flaw means that after a single approval by a repository administrator on a benign fork PR, the user is permanently trusted to run arbitrary workflows on the repository's CI infrastructure. The issue was introduced in commit edf98a2dc3 on 2023-02-24 and affects all releases from v1.20.0 through versions prior to 1.26.3, including the latest development builds. No official fix is available yet. The vulnerability requires an authenticated user with fork capability and one-time interaction from a repository admin. It was live-verified on Gitea main branch in May 2026.

Potential Impact

An attacker with a standard authenticated account capable of forking the repository can gain persistent ability to execute arbitrary workflow code on the repository's CI runners after a single approval of a benign fork PR workflow by a repository administrator. This allows execution of arbitrary shell commands with network access and repository source access, potentially leading to code execution, data exposure, and disruption of CI infrastructure. The vulnerability undermines the intended security gate for fork PR workflows, effectively granting permanent elevated trust to the attacker within the affected repository.

Mitigation Recommendations

No official fix or patch is currently available for this vulnerability. Repository administrators should be aware that approving a fork PR workflow run from a new contributor permanently grants that user the ability to run arbitrary workflows without further approval. As a temporary mitigation, administrators should avoid approving fork PR workflow runs from untrusted contributors until a fix is released. Monitor Gitea vendor advisories for updates and apply official patches once available.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
Gitea
Date Reserved
2026-06-30T18:57:20.614Z
Cvss Version
3.1
State
PUBLISHED
Remediation Level
null
Gcve Source
db.gcve.eu

Threat ID: 6a483c9d27e9c79719d7f5ce

Added to database: 07/03/2026, 22:50:05 UTC

Last enriched: 07/22/2026, 01:47:03 UTC

Last updated: 07/26/2026, 11:21:13 UTC

Views: 195

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses