Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content (CVE-2026-57886)

0
Medium
Published: 07/21/2026 (07/21/2026, 20:22:58 UTC)
Source: GCVE Database
Product: code.gitea.io/gitea

Description

Gitea contains a vulnerability in its issue and comment attachment update functionality where attachment UUIDs are accepted without verifying repository ownership. An authenticated attacker who can edit issues or comments in a repository they can read can re-link a known victim attachment UUID to their own issue or comment. This causes subsequent access checks to use the attacker's repository authorization context, potentially exposing private attachment content. The issue affects versions prior to 1.27.0 and remains unpatched at the time of reporting. The vulnerability does not require write access to the victim repository but does require knowledge of the attachment UUID. A fix involves adding repository and linkage validation before updating attachments.

CVSS v3.1

Score 5.9medium

Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N

Affected software

Goghsa
code.gitea.io/gitea
Affected versions
<1.27.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/22/2026, 00:52:12 UTC

Technical Analysis

Gitea's issue and comment attachment update paths accept attachment UUIDs without verifying that the attachment belongs to the target repository. This allows an authenticated attacker with edit permissions on an issue or comment in a repository they can read to re-link a victim's attachment UUID to their own issue or comment. The attachment's repository ID remains that of the victim, but the linked issue/comment repository ID changes to the attacker's repository, causing access checks to be performed against the attacker's repository authorization context. This can disclose private attachments if the attacker has obtained the UUID through prior exposure. The vulnerability affects the web issue/comment attachment handling component and was confirmed in the main branch commit a39b2775edcb3ba53def96794491b91335117d81 (v1.27.0-dev-352-ga39b2775ed). It is not fixed at the time of validation. The issue is due to missing validation that the attachment's RepoID matches the repository of the target issue/comment during attachment updates. A similar check exists for release attachments but is missing for issue/comment attachments.

Potential Impact

An attacker who can edit an issue or comment in a repository they can read can re-link a victim's attachment UUID to their own issue or comment. This causes the attachment download path to authorize access based on the attacker's repository permissions rather than the victim's repository. Consequently, private attachments can be disclosed to the attacker if they have obtained the attachment UUID through legitimate prior access or other means. The attack does not require write access to the victim repository, only knowledge of the attachment UUID and edit rights in the attacker's repository. This leads to unauthorized disclosure of private issue/comment attachments.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The suggested fix is to add repository and linkage validation before updating issue/comment attachments to ensure attachments belong to the target repository and are not already linked elsewhere. Until a patch is available, restrict issue/comment edit permissions to trusted users and avoid exposing attachment UUIDs unnecessarily.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-6c6r-5xr4-cr5m
Osv Schema Version
1.4.0
Aliases
["CVE-2026-57886"]
Ecosystems
["Go"]
Database Specific Severity
MODERATE
Cvss Version
3.1

Threat ID: 6a600abb9c2644c7f8fe2b8b

Added to database: 07/22/2026, 00:11:39 UTC

Last enriched: 07/22/2026, 00:52:12 UTC

Last updated: 07/31/2026, 12:28:12 UTC

Views: 28

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses