Executive brief
Gitea, a popular self-hosted Git repository platform, contains a vulnerability in its organization permission APIs that allows unauthorized users to discover hidden organization members and access information about private organizations. An attacker without authentication can exploit this flaw to enumerate sensitive organizational structure and membership data that should remain confidential, potentially aiding reconnaissance for targeted attacks.
Technical details
The vulnerability is an access control flaw (CWE-284) in Gitea's organization permission API endpoints. The root cause is insufficient visibility checks when handling hidden members and private organizations; specifically, a wrong parameter was passed to the HasOrgOrUserVisible function in routers/api/v1/org/org.go. The attack vector is network-based with no authentication required, low attack complexity, and no user interaction needed. An attacker can enumerate hidden organization members and retrieve information about private organizations that they should not have access to. The vulnerability is patched in Gitea 1.25.5 and later versions via commits 57b5ed3 and 96515c0, which correct the visibility check logic and add integration tests to prevent regression.
Affected products
- Gitea Gitea < 1.25.5
Timeline
- 2026-07-03: disclosed: CVE-2026-25712 published to NVD and GitHub Advisory Database
- 2026-03-16: patched: Fix released in Gitea 1.25.5