Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-94205: Gitea runs unapproved fork code on main repository

CVE-2026-94205 · published 3 days ago
Summary

In Gitea, when a maintainer triggers certain actions on a pull request from a fork, the system may start the workflow without requiring explicit approval, even though the code comes from the fork. This can let unreviewed code execute on the repository's own runners, potentially exposing the system to risk. Administrators should review and adjust the workflow approval settings to ensure all fork‑originated actions require manual approval before they run.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
gitea gitea <= 1.27.3
Original advisory text
Gitea fork workflow approval bypass through maintainer-triggered events
Gitea Actions decided whether a fork pull request run needed approval based on the user who triggered the event rather than the pull request author. For `pull_request` activity triggered by a maintainer during ordinary triage, such as adding a label, the run was created without requiring approval, while the workflow definition was still taken from the fork head. Where Actions is enabled and a matching runner is registered, fork-controlled workflow code could run on the base repository's runners without an explicit approval.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-441Unintended Proxy or Intermediary ('Confused Deputy')
CWE-863Incorrect Authorization
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Sources
CVE-2026-94205 · MITRE
Track software like this
Free during beta