Executive brief
A security flaw in Gitea, a popular self-hosted Git service, allows any user with SSH access to bypass permission checks and download large files (LFS objects) from private repositories they do not own. This could lead to the unauthorized exposure of sensitive source code, proprietary assets, or internal documentation stored within an organization's private projects. The issue is particularly severe for instances where user registration is open to the public.
Technical details
A logic error exists in Gitea's `getAccessMode` function within `cmd/serv.go`. When an SSH user provides a malformed or unknown LFS sub-verb (other than 'upload' or 'download'), the system defaults to `AccessModeNone` (0) in production environments instead of panicking. During subsequent permission checks in `routers/private/serv.go`, the comparison `userMode < mode` (where `mode` is 0) evaluates to false, effectively granting access to private repositories. This allows an attacker to obtain a valid JWT token for LFS operations. While write operations are validated later, read (download) operations do not verify the 'Op' claim in the token, enabling unauthorized data retrieval. This affects Gitea versions 1.23.0 through 1.26.2 and is fixed in 1.26.3.
Affected products
- Gitea Gitea >= 1.23.0, < 1.26.3
Timeline
- 2026-07-01: disclosed
- 2026-07-03: advisory: NVD publication date
- 2026-07-21: patched: GitHub Advisory reviewed and updated