Impact
When migrating repositories, the Gitea server follows HTTP redirects after applying URL allow or block validation, which can be exploited to direct the server to an attacker‑controlled external host. This flaw can lead to the internal repository contents being sent to a malicious endpoint, compromising data confidentiality. The weakness is a type of HTTP response redirection vulnerability (CWE‑918).
Affected Systems
The vulnerability is present in the Gitea Open Source Git Server. No specific product versions are listed, meaning all installations potentially contain the affected logic.
Risk and Exploitability
The EPSS score is not available and the vulnerability has not been listed in the CISA KEV catalog. Despite the lack of public exploit data, the flaw can be triggered by performing a migration with a crafted URL, so an attacker who can initiate migrations or is on the internal network can exfiltrate repository data. The likely attack vector is inferred to be internal or authenticated, requiring the adversary to have migration privileges.
OpenCVE Enrichment
Github GHSA