Executive brief
Gitea is an open-source self-hosted Git service used by organizations to manage source code. A vulnerability in its Git push handler allows users with administrative access to a specific repository to silently change its visibility from private to public or modify its template status. Because this action bypasses standard logging and notification systems, an insider could expose proprietary code or sensitive configuration files without leaving an audit trail or alerting other administrators.
Technical details
The vulnerability exists in the `HookPostReceive` function within `routers/private/hook_post_receive.go`. Gitea processes undocumented Git push options (`repo.private` and `repo.template`) using the `-o` flag during a `git push`. While intended for 'push-to-create' workflows, these options are processed for existing repositories without triggering the standard repository service logic. Consequently, changes to visibility or template status bypass the activity log, webhook events, and the `updated_at` timestamp update due to the use of `UpdateRepositoryColsNoAutoTime`. An attacker with admin-collaborator or owner permissions can use this to exfiltrate data or perform supply-chain attacks by silently toggling template designations. The issue is fixed in version 1.27.0.
Affected products
- Gitea Gitea < 1.27.0
Timeline
- 2026-07-13: patched: Fixed in version 1.27.0
- 2026-07-21: advisory: GitHub Advisory published