Impact
The vulnerability allows webhooks created by a collaborator to continue firing after the collaborator’s repository access has been revoked, resulting in persistent real‑time exfiltration of private repository content. This defect indicates a failure in the repository revocation process to clean up associated webhook configurations, enabling unauthorized data disclosure.
Affected Systems
The flaw impacts the Gitea Open Source Git Server. Specific product versions are not provided, so all deployed instances should be evaluated for remediation.
Risk and Exploitability
No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation data yet implying a potentially severe risk to confidentiality if exploited. The likely attack vector involves a repository administrator revoking a collaborator’s access; if the webhook remains active, that administrator can obtain confidential data through the webhook payloads. Developers should therefore treat this as a high‑severity authorization issue and address it promptly.
OpenCVE Enrichment
Github GHSA