Impact
The Gitea push mirror API incorrectly evaluates permission by referencing the repository owner rather than the user that invoked the operation. This mischeck allows an admin user who does not normally have permission to use local filesystem paths to create a push mirror that points to any local repository path on the server on instances where the global setting IMPORT_LOCAL_PATHS = true. When the mirror synchronises, Gitea pushes the repository’s refs into the target repository using the Gitea process’s privileges. The vulnerability is a classic authorization flaw (CWE-863) that can result in unauthorized modification of local Git repositories and potentially the injection of malicious commits or alteration of repository history.
Affected Systems
This flaw affects Gitea installations that enable local path imports. While the specific affected versions are not enumerated in the advisory, the fix was introduced in release 28.1.0, so any Gitea instance running a version older than 28.1.0 is potentially vulnerable. The problem is present regardless of the number of repositories or the deployment topology.
Risk and Exploitability
No EPSS score is publicly available and the vulnerability is not listed in CISA’s KEV catalog, indicating there are currently no known active exploits. The attack requires a user with repository administration privileges and the setting IMPORT_LOCAL_PATHS enabled. Because the flaw permits writing to arbitrary local repositories with the Gitea process’s effective permissions, an attacker could persistently tamper with committed contents, corrupt repository history, or introduce backdoors. Although the exploitation is straightforward within the application, its impact is confined to the local server environment and requires administrative authentication to trigger.
OpenCVE Enrichment