Description
With `[repository] FORCE_PRIVATE = true`, Gitea creates new repositories as private, but the post-receive hook still applied the `repo.private=false` push option to an empty repository created by push. Any user who can create repositories could make their new repository public in violation of the instance policy. The default configuration is not affected.
Published:
2026-10-06
Score:
n/a
EPSS:
n/a
KEV:
No
Impact:
n/a
Action:
n/a
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 06 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | With `[repository] FORCE_PRIVATE = true`, Gitea creates new repositories as private, but the post-receive hook still applied the `repo.private=false` push option to an empty repository created by push. Any user who can create repositories could make their new repository public in violation of the instance policy. The default configuration is not affected. | |
| Title | Gitea push-to-create bypass of FORCE_PRIVATE policy | |
| Weaknesses | CWE-863 | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Gitea
Published:
Updated: 2026-10-06T21:36:01.187Z
Reserved: 2026-10-04T22:02:04.881Z
Link: CVE-2026-89182
No data.
Status : Received
Published: 2026-10-06T22:17:07.690
Modified: 2026-10-06T22:17:07.690
Link: CVE-2026-89182
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-863
Incorrect Authorization