Impact
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information. Based on the description, this appears to be a missing authorization check (CWE-862).
Affected Systems
The affected product is the Gitea Open Source Git Server. Versions 1.26.1 and any earlier releases are impacted. Users operating these versions should be aware that source links can be accessed without proper permission checks.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity. An EPSS score of 41% indicates a moderate to high likelihood of exploitation. The CVE is not listed in the CISA KEV catalog, meaning no known active exploits have been reported. Based on the description, it is inferred that an attacker could by accessing Composer package source links without proper permission checks.
OpenCVE Enrichment
Github GHSA