Impact
The vulnerability allows an attacker to re‑link attachments from one repository to an issue or comment in another repository, thereby exposing private attachment content that should not be publicly accessible. This flaw arises from insufficient access control and missing authorization checks, as identified by CWE-639 and CWE-862.
Affected Systems
The affected product is Gitea Open Source Git Server. No specific version information is provided in the advisory.
Risk and Exploitability
The exploit probability is unknown because EPSS is not available, and the vulnerability is not listed in CISA KEV. The lack of a CVSS score limits precise severity assessment, but the potential to leak private data suggests a moderate to high risk. The likely attack vector is through the UI or API mechanisms that enable attachment re‑linking across repositories, inferred from the description of the issue.
OpenCVE Enrichment
Github GHSA