Gitea: Permanent Fork PR Workflow Approval Gate Bypass (CVE-2026-58424)
Gitea Actions contains a vulnerability in the fork pull request workflow approval gate that allows an attacker with a single unprivileged account and one-time maintainer approval on a benign fork PR to permanently bypass approval for all future fork PR workflow runs from that user on the same repository. This bypass occurs because the approval check only verifies if the user has any previously approved run in the repository, without considering the pull request, commit, or workflow contents. The vulnerability affects all Gitea versions from v1.20.0 onward and remains unpatched as of this disclosure.
AI Analysis
Technical Summary
The vulnerability (CVE-2026-58424) resides in Gitea Actions' approval gate for workflows triggered by fork pull requests. The function ifNeedApproval incorrectly skips approval if the triggering user has any previously approved workflow run in the repository, regardless of the PR, commit, or workflow file. This logic flaw means that after a single approval by a repository administrator on a benign fork PR, the user is permanently trusted to run arbitrary workflows on the repository's CI infrastructure. The issue was introduced in commit edf98a2dc3 on 2023-02-24 and affects all releases from v1.20.0 through versions prior to 1.26.3, including the latest development builds. No official fix is available yet. The vulnerability requires an authenticated user with fork capability and one-time interaction from a repository admin. It was live-verified on Gitea main branch in May 2026.
Potential Impact
An attacker with a standard authenticated account capable of forking the repository can gain persistent ability to execute arbitrary workflow code on the repository's CI runners after a single approval of a benign fork PR workflow by a repository administrator. This allows execution of arbitrary shell commands with network access and repository source access, potentially leading to code execution, data exposure, and disruption of CI infrastructure. The vulnerability undermines the intended security gate for fork PR workflows, effectively granting permanent elevated trust to the attacker within the affected repository.
Mitigation Recommendations
No official fix or patch is currently available for this vulnerability. Repository administrators should be aware that approving a fork PR workflow run from a new contributor permanently grants that user the ability to run arbitrary workflows without further approval. As a temporary mitigation, administrators should avoid approving fork PR workflow runs from untrusted contributors until a fix is released. Monitor Gitea vendor advisories for updates and apply official patches once available.
Gitea: Permanent Fork PR Workflow Approval Gate Bypass (CVE-2026-58424)
Description
Gitea Actions contains a vulnerability in the fork pull request workflow approval gate that allows an attacker with a single unprivileged account and one-time maintainer approval on a benign fork PR to permanently bypass approval for all future fork PR workflow runs from that user on the same repository. This bypass occurs because the approval check only verifies if the user has any previously approved run in the repository, without considering the pull request, commit, or workflow contents. The vulnerability affects all Gitea versions from v1.20.0 onward and remains unpatched as of this disclosure.
CVSS v3.1
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability (CVE-2026-58424) resides in Gitea Actions' approval gate for workflows triggered by fork pull requests. The function ifNeedApproval incorrectly skips approval if the triggering user has any previously approved workflow run in the repository, regardless of the PR, commit, or workflow file. This logic flaw means that after a single approval by a repository administrator on a benign fork PR, the user is permanently trusted to run arbitrary workflows on the repository's CI infrastructure. The issue was introduced in commit edf98a2dc3 on 2023-02-24 and affects all releases from v1.20.0 through versions prior to 1.26.3, including the latest development builds. No official fix is available yet. The vulnerability requires an authenticated user with fork capability and one-time interaction from a repository admin. It was live-verified on Gitea main branch in May 2026.
Potential Impact
An attacker with a standard authenticated account capable of forking the repository can gain persistent ability to execute arbitrary workflow code on the repository's CI runners after a single approval of a benign fork PR workflow by a repository administrator. This allows execution of arbitrary shell commands with network access and repository source access, potentially leading to code execution, data exposure, and disruption of CI infrastructure. The vulnerability undermines the intended security gate for fork PR workflows, effectively granting permanent elevated trust to the attacker within the affected repository.
Mitigation Recommendations
No official fix or patch is currently available for this vulnerability. Repository administrators should be aware that approving a fork PR workflow run from a new contributor permanently grants that user the ability to run arbitrary workflows without further approval. As a temporary mitigation, administrators should avoid approving fork PR workflow runs from untrusted contributors until a fix is released. Monitor Gitea vendor advisories for updates and apply official patches once available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Gitea
- Date Reserved
- 2026-06-30T18:57:20.614Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Gcve Source
- db.gcve.eu
Threat ID: 6a483c9d27e9c79719d7f5ce
Added to database: 07/03/2026, 22:50:05 UTC
Last enriched: 07/22/2026, 01:47:03 UTC
Last updated: 07/26/2026, 11:21:13 UTC
Views: 195
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.