
Critical Gitea Vulnerability Lets Public Repository Tokens Trigger Private Workflows
A critical authorization flaw in Gitea, tracked as CVE-2026-58443, allows API tokens restricted to public repositories to indirectly write into private repositories and trigger their Actions workflows. The vulnerability, disclosed via GHSA-xxjv-752h-3vp2 based on a report from ohxorud-dev, carries a CVSS v3.1, placing it in the Critical severity band. The bug lives in the pull […]
The post Critical Gitea Vulnerability Lets Public Repository Tokens Trigger Private Workflows appeared first on Cyber Security News.