Description
Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fhx7-m96w-mv29 | Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration |
References
History
Fri, 03 Jul 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets. | |
| Title | Gitea organization forks can expose organization secrets without create permission | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Gitea
Published:
Updated: 2026-07-03T20:19:30.648Z
Reserved: 2026-03-03T03:25:28.700Z
Link: CVE-2026-22555
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA