Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content (CVE-2026-57886)
Gitea contains a vulnerability in its issue and comment attachment update functionality where attachment UUIDs are accepted without verifying repository ownership. An authenticated attacker who can edit issues or comments in a repository they can read can re-link a known victim attachment UUID to their own issue or comment. This causes subsequent access checks to use the attacker's repository authorization context, potentially exposing private attachment content. The issue affects versions prior to 1.27.0 and remains unpatched at the time of reporting. The vulnerability does not require write access to the victim repository but does require knowledge of the attachment UUID. A fix involves adding repository and linkage validation before updating attachments.
AI Analysis
Technical Summary
Gitea's issue and comment attachment update paths accept attachment UUIDs without verifying that the attachment belongs to the target repository. This allows an authenticated attacker with edit permissions on an issue or comment in a repository they can read to re-link a victim's attachment UUID to their own issue or comment. The attachment's repository ID remains that of the victim, but the linked issue/comment repository ID changes to the attacker's repository, causing access checks to be performed against the attacker's repository authorization context. This can disclose private attachments if the attacker has obtained the UUID through prior exposure. The vulnerability affects the web issue/comment attachment handling component and was confirmed in the main branch commit a39b2775edcb3ba53def96794491b91335117d81 (v1.27.0-dev-352-ga39b2775ed). It is not fixed at the time of validation. The issue is due to missing validation that the attachment's RepoID matches the repository of the target issue/comment during attachment updates. A similar check exists for release attachments but is missing for issue/comment attachments.
Potential Impact
An attacker who can edit an issue or comment in a repository they can read can re-link a victim's attachment UUID to their own issue or comment. This causes the attachment download path to authorize access based on the attacker's repository permissions rather than the victim's repository. Consequently, private attachments can be disclosed to the attacker if they have obtained the attachment UUID through legitimate prior access or other means. The attack does not require write access to the victim repository, only knowledge of the attachment UUID and edit rights in the attacker's repository. This leads to unauthorized disclosure of private issue/comment attachments.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The suggested fix is to add repository and linkage validation before updating issue/comment attachments to ensure attachments belong to the target repository and are not already linked elsewhere. Until a patch is available, restrict issue/comment edit permissions to trusted users and avoid exposing attachment UUIDs unnecessarily.
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content (CVE-2026-57886)
Description
Gitea contains a vulnerability in its issue and comment attachment update functionality where attachment UUIDs are accepted without verifying repository ownership. An authenticated attacker who can edit issues or comments in a repository they can read can re-link a known victim attachment UUID to their own issue or comment. This causes subsequent access checks to use the attacker's repository authorization context, potentially exposing private attachment content. The issue affects versions prior to 1.27.0 and remains unpatched at the time of reporting. The vulnerability does not require write access to the victim repository but does require knowledge of the attachment UUID. A fix involves adding repository and linkage validation before updating attachments.
CVSS v3.1
Score 5.9medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Gitea's issue and comment attachment update paths accept attachment UUIDs without verifying that the attachment belongs to the target repository. This allows an authenticated attacker with edit permissions on an issue or comment in a repository they can read to re-link a victim's attachment UUID to their own issue or comment. The attachment's repository ID remains that of the victim, but the linked issue/comment repository ID changes to the attacker's repository, causing access checks to be performed against the attacker's repository authorization context. This can disclose private attachments if the attacker has obtained the UUID through prior exposure. The vulnerability affects the web issue/comment attachment handling component and was confirmed in the main branch commit a39b2775edcb3ba53def96794491b91335117d81 (v1.27.0-dev-352-ga39b2775ed). It is not fixed at the time of validation. The issue is due to missing validation that the attachment's RepoID matches the repository of the target issue/comment during attachment updates. A similar check exists for release attachments but is missing for issue/comment attachments.
Potential Impact
An attacker who can edit an issue or comment in a repository they can read can re-link a victim's attachment UUID to their own issue or comment. This causes the attachment download path to authorize access based on the attacker's repository permissions rather than the victim's repository. Consequently, private attachments can be disclosed to the attacker if they have obtained the attachment UUID through legitimate prior access or other means. The attack does not require write access to the victim repository, only knowledge of the attachment UUID and edit rights in the attacker's repository. This leads to unauthorized disclosure of private issue/comment attachments.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The suggested fix is to add repository and linkage validation before updating issue/comment attachments to ensure attachments belong to the target repository and are not already linked elsewhere. Until a patch is available, restrict issue/comment edit permissions to trusted users and avoid exposing attachment UUIDs unnecessarily.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-6c6r-5xr4-cr5m
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-57886"]
- Ecosystems
- ["Go"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a600abb9c2644c7f8fe2b8b
Added to database: 07/22/2026, 00:11:39 UTC
Last enriched: 07/22/2026, 00:52:12 UTC
Last updated: 07/31/2026, 12:28:12 UTC
Views: 28
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.