Executive brief
Gitea is an open-source platform for hosting software development projects. A security flaw in its programming interface (API) allows an attacker who has a limited-access token (such as one used for automated testing) to create a new, fully-privileged token. This allows the attacker to gain complete control over a user's account and data without needing to know their password.
Technical details
A privilege escalation vulnerability exists in Gitea's API due to a logic error in the authentication middleware. The `reqBasicOrRevProxyAuth` middleware, intended to require password-based authentication for sensitive operations like token creation, can be bypassed by providing a Personal Access Token (PAT) in the `Authorization: Basic <token>:x-oauth-basic` format. The backend incorrectly sets `IsBasicAuth=true` for these requests. Furthermore, the `CreateAccessToken` handler fails to implement a 'scope ceiling' check, allowing a caller with a restricted token to mint a new token with the 'all' scope. This allows an attacker with any valid token to escalate to full account privileges. Fixed in version 1.27.0.
Affected products
- Gitea Gitea < 1.27.0
Timeline
- 2026-07-13: disclosed
- 2026-07-21: advisory