
Critical Gitea Vulnerability Enables Private Repository Writes and Actions Workflow Triggers
Gitea users are urged to update immediately after a critical vulnerability was disclosed that allows public-only repository access tokens to indirectly write to private pull request branches and trigger private Actions workflows. Tracked as CVE-2026-58443, the vulnerability affects Gitea versions up to v1.26.4 and has been fixed in v1.27.0. The flaw exists in Gitea’s pull […]
The post Critical Gitea Vulnerability Enables Private Repository Writes and Actions Workflow Triggers appeared first on Cyber Security News.