Description
Public-only repository tokens can update private PR head branches
Published: 2026-08-13
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows a user who possesses a public‑only repository token to push commits that modify the head branch of a private pull request. Because the token is not restricted by repository scope, the attacker can alter code that is slated for review in a private repository. The weakness is a failure of authorization enforcement at the token level and is classified as Wrong or Incomplete Authorization (CWE‑863). The potential impact is the injection of malicious code into branches prior to review, thereby compromising the integrity and confidentiality of the repository.

Affected Systems

Gitea Open Source Git Server is impacted. No specific version information is provided in the available data, so the precise set of vulnerable releases cannot be stated.

Risk and Exploitability

No EPSS score or KEV listing is available for this issue, and the CVSS score is not published. The attack requires only possession of a public‑only token, which can be generated by any account that is allowed to create such tokens. As a result, the vulnerability has a high potential impact for any organization using public‑only tokens in private repositories and can be exploited without additional network or user interaction vulnerabilities.

Generated by OpenCVE AI on August 13, 2026 at 19:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Gitea to the latest released version that contains the vendor patch for this issue by checking the official Gitea release notes and applying the update.
  • Restrict the scopes of repository tokens so that public‑only tokens are not granted for private repositories, ensuring that only appropriate, minimal‑scope tokens are used for access.
  • Enable monitoring and alerting for any unauthorized pushes to private pull request head branches to detect potential misuse early.

Generated by OpenCVE AI on August 13, 2026 at 19:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-xxjv-752h-3vp2 Gitea: Public-only repository tokens can update private PR head branches
History

Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Gitea
Gitea gitea Open Source Git Server
Vendors & Products Gitea
Gitea gitea Open Source Git Server

Thu, 13 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description Public-only repository tokens can update private PR head branches
Title Public-only repository tokens can update private PR head branches
Weaknesses CWE-863
References

Subscriptions

Gitea Gitea Open Source Git Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Gitea

Published:

Updated: 2026-08-13T16:44:55.935Z

Reserved: 2026-06-30T18:57:20.616Z

Link: CVE-2026-58443

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T17:17:28.330

Modified: 2026-08-13T17:17:28.330

Link: CVE-2026-58443

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T19:45:17Z

Weaknesses