Description
The Gitea push mirror API checked whether the repository owner, instead of the requesting user, may use local file system paths. On instances with `[security] IMPORT_LOCAL_PATHS = true`, a repository administrator who is not allowed to import local paths could add a push mirror to a local path on the server when the repository owner has that permission. Gitea then pushed the repository's refs into an existing Git repository at that path with the permissions of the Gitea process.
Published: 2026-10-06
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthorized modification of local Git repositories
Action: Immediate Patch
AI Analysis

Impact

The Gitea push mirror API incorrectly evaluates permission by referencing the repository owner rather than the user that invoked the operation. This mischeck allows an admin user who does not normally have permission to use local filesystem paths to create a push mirror that points to any local repository path on the server on instances where the global setting IMPORT_LOCAL_PATHS = true. When the mirror synchronises, Gitea pushes the repository’s refs into the target repository using the Gitea process’s privileges. The vulnerability is a classic authorization flaw (CWE-863) that can result in unauthorized modification of local Git repositories and potentially the injection of malicious commits or alteration of repository history.

Affected Systems

This flaw affects Gitea installations that enable local path imports. While the specific affected versions are not enumerated in the advisory, the fix was introduced in release 28.1.0, so any Gitea instance running a version older than 28.1.0 is potentially vulnerable. The problem is present regardless of the number of repositories or the deployment topology.

Risk and Exploitability

No EPSS score is publicly available and the vulnerability is not listed in CISA’s KEV catalog, indicating there are currently no known active exploits. The attack requires a user with repository administration privileges and the setting IMPORT_LOCAL_PATHS enabled. Because the flaw permits writing to arbitrary local repositories with the Gitea process’s effective permissions, an attacker could persistently tamper with committed contents, corrupt repository history, or introduce backdoors. Although the exploitation is straightforward within the application, its impact is confined to the local server environment and requires administrative authentication to trigger.

Generated by OpenCVE AI on October 7, 2026 at 00:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Gitea to version 28.1.0 or newer to apply the official fix.
  • Disable the global IMPORT_LOCAL_PATHS setting if local path mirroring is not required in your deployment.
  • Restrict administrator roles that can create push mirrors, ensuring they only have permission to use remote git URLs.

Generated by OpenCVE AI on October 7, 2026 at 00:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Description The Gitea push mirror API checked whether the repository owner, instead of the requesting user, may use local file system paths. On instances with `[security] IMPORT_LOCAL_PATHS = true`, a repository administrator who is not allowed to import local paths could add a push mirror to a local path on the server when the repository owner has that permission. Gitea then pushed the repository's refs into an existing Git repository at that path with the permissions of the Gitea process.
Title Gitea push mirror local path check uses the repository owner
Weaknesses CWE-863
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Gitea

Published:

Updated: 2026-10-06T21:17:09.942Z

Reserved: 2026-10-04T22:02:04.866Z

Link: CVE-2026-86684

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T22:17:07.570

Modified: 2026-10-06T22:17:07.570

Link: CVE-2026-86684

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T00:15:07Z

Weaknesses