Executive brief
Gitea is a self-hosted software development service similar to GitHub. A security flaw in its issue-tracking system allows an authorized user to remove dependency links and post automated comments on private repositories they do not have permission to access. While this does not expose the contents of the private code, it allows an attacker to tamper with project management data and inject unauthorized comments into private workflows.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the `RemoveDependency` function within `routers/web/repo/issue_dependency.go`. The function accepts a `removeDependencyID` parameter and fetches the target issue using its global numeric ID without verifying if the requesting user has read or write permissions for the repository containing that issue. An attacker with write access to any repository can exploit this to delete existing cross-repository dependency links and trigger an automated "removed dependency" comment on issues in private repositories. This bypasses the authorization checks correctly implemented in the corresponding `AddDependency` function. The issue is fixed in Gitea version 1.27.0.
Affected products
- Gitea Gitea < 1.27.0
Timeline
- 2026-07-13: disclosed: Initial report to vendor
- 2026-07-21: advisory: GitHub Advisory published
- 2026-07-21: patched: Fixed in version 1.27.0