PT-2026-63298 · Go · Gitea.Dev

CVE-2026-58431

·

Publicado

2026-07-21

·

Atualizado

2026-07-21

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Summary

Gitea's /api/v1/teams/{id} API routes do not correctly enforce the public-only access token restriction.
A public-only token is intended to limit API access to public repositories and public organizations. However, several team API routes continue to return private team repository metadata and private team activity feed entries when called with a public-only token.

Details

The /api/v1/teams/{teamid} route group uses:
go
orgAssignment(false, true)
This loads ctx.Org.Team, but does not load ctx.Org.Organization.
The checkTokenPublicOnly middleware checks organization visibility through ctx.Org.Organization. When ctx.Org.Organization is nil, the organization visibility check silently passes.
In addition, the team repository handlers return repositories without applying repository-level public-only filtering:
go
repo model.GetTeamRepositories(...)
convert.ToRepo(...)
They do not call:
go
ctx.TokenCanAccessRepo(repo)
The team activity feed handler also sets:
go
IncludePrivate: true
but does not apply:
go
opts.ApplyPublicOnly(ctx.PublicOnly)

PoC

Vulnerability is verified on latest gitea release (1.26.2) and nightly build. Frist, create a public-only organization-scoped token for a user who is a member of a team in a private org with private repositories:
image image
Use the returned token to request team repositories:
image
Expected result: Private repositories should be hidden or rejected for a public-only token. Actual result: Private team repository metadata is returned.
The team activity feed endpoint can be tested similarly:
image

Impact

A public-only token can access private team resources that should be hidden from that token.

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-58431
GHSA-H56G-4QW7-2MXG

Produtos afetados

Gitea.Dev