Junglewise Threat Intelligence

Gitea auth bypass in API fork endpoint

Severity: medium · CVSS 5.3 · Published 2026-07-21

Technologies: code.gitea.io/gitea (Go), Gitea. Vendors: Go, Gitea.

Executive brief

Gitea is an open-source self-hosted software development platform. A security flaw in its programming interface (API) allows organization members to create new code repositories even if they have been specifically restricted from doing so by administrators. This bypass could lead to unauthorized use of organization resources and potentially expose the organization to additional security risks through unmonitored automated workflows.

Technical details

An authorization bypass exists in Gitea's API fork endpoint (POST /api/v1/repos/{owner}/{repo}/forks). The root cause is an insufficient permission check in 'routers/api/v1/repo/fork.go' that only verifies organization membership (IsOrgMember) rather than specific repository creation privileges (CanCreateOrgRepo). An authenticated attacker who is a member of an organization but lacks repository creation rights can successfully fork repositories into that organization via the API, bypassing restrictions enforced in the web UI. This vulnerability is addressed in Gitea version 1.26.0.

Affected products

  • Gitea Gitea < 1.26.0

Timeline

  • 2026-06-21: disclosed
  • 2026-07-21: advisory
  • 1.26.0: patched

References

Related threats