Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-86684— Gitea push mirror local path check uses the repository owner

Quick assessment

Affected
Gitea Gitea
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Gitea 推送镜像 API 在检查是否允许使用本地文件系统路径时,仅验证了仓库所有者(repository owner)的权限,而未验证实际发起请求的用户。在配置了 的 Gitea 实例中,若仓库所有者拥有使用本地路径的权限,则即使仓库管理员(repository administrator)本身无权导入本地路径,该管理员也可以通过推送镜像功能,将一个推送镜像指向服务器上的一个本地路径。随后,Gitea 会以 Gitea 进程自身的权限,将该仓库的引用(refs)推送到该路径上已存在的 Git 仓库中。

AI Predicted 7.8 Difficulty: Easy
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-86684

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Gitea push mirror local path check uses the repository owner
Source: CVE Program / CVE List V5
Vulnerability Description
The Gitea push mirror API checked whether the repository owner, instead of the requesting user, may use local file system paths. On instances with `[security] IMPORT_LOCAL_PATHS = true`, a repository administrator who is not allowed to import local paths could add a push mirror to a local path on the server when the repository owner has that permission. Gitea then pushed the repository's refs into an existing Git repository at that path with the permissions of the Gitea process.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Gitea Gitea 1.18.0 ~ 28.0.0 -

II. Public POCs for CVE-2026-86684

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-86684

请登录查看更多情报信息。

Other References for CVE-2026-86684 (5)

Same Patch Batch · Gitea · 2026-10-06 · 30 CVEs total

CVE-2026-96399 Gitea denial of service through external issue tracker patterns
CVE-2026-97626 Gitea profile feed disclosure bypassing user visibility
CVE-2026-96594 Gitea repository media API stored XSS
CVE-2026-104633 Gitea migration memory exhaustion from zero page size
CVE-2026-101023 Gitea OAuth2 refresh token grant accepts access tokens
CVE-2026-105267 Gitea tag delete route deletes releases without release permission
CVE-2026-105268 Gitea issue attachment API allows changing comment attachments
CVE-2026-89182 Gitea push-to-create bypass of FORCE_PRIVATE policy
CVE-2026-97208 Gitea push mirror API bypass of DISABLE_NEW_PUSH policy
CVE-2026-73278 Gitea WebAuthn bypass during OAuth and OIDC sign-in
CVE-2026-79960 Gitea deploy key pushes acting as the repository owner
CVE-2026-70357 Gitea repository migration SSRF through DNS rebinding
CVE-2026-96580 Gitea Actions memory exhaustion through large static matrices
CVE-2026-96589 Gitea private repository access retained after rejected transfer
CVE-2026-96400 Gitea migration SSRF to reserved addresses through ALLOWED_DOMAINS
CVE-2026-94205 Gitea fork workflow approval bypass through maintainer-triggered events
CVE-2026-96404 Gitea installer authentication bypass for existing accounts
CVE-2026-104626 Gitea fork workflow job revival through later approval
CVE-2026-104632 Gitea fork workflow approval bypass through cancel and rerun
CVE-2026-104636 Gitea SSRF through Git HTTP redirects in mirrors and fetches

Showing top 20 of 30 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-86684

No comments yet


Leave a comment