CVE-2026-86684

Source
https://cve.org/CVERecord?id=CVE-2026-86684
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86684.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-86684
Aliases
  • GHSA-7v5j-mph8-9w6g
Published
2026-10-06T21:17:09Z
Modified
2026-10-08T10:45:15Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Gitea push mirror local path check uses the repository owner
Details

The Gitea push mirror API checked whether the repository owner, instead of the requesting user, may use local file system paths. On instances with [security] IMPORT_LOCAL_PATHS = true, a repository administrator who is not allowed to import local paths could add a push mirror to a local path on the server when the repository owner has that permission. Gitea then pushed the repository's refs into an existing Git repository at that path with the permissions of the Gitea process.

Database specific
{
    "cna_assigner": "Gitea",
    "cwe_ids": [
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86684.json"
}
References

Affected packages

Git / github.com/go-gitea/gitea

Affected ranges

Type
GIT
Repo
https://github.com/go-gitea/gitea
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.18.0"
        },
        {
            "last_affected": "28.0.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v1.*
v1.18.0-dev
v1.18.0-rc0
v1.19.0-dev
v1.19.0-rc0
v1.20.0-dev
v1.20.0-rc0
v1.21.0-dev
v1.21.0-rc0
v1.22.0-dev
v1.22.0-rc0
v1.22.0-rc1
v1.23.0-dev
v1.24.0-dev
v1.25.0-dev
v1.26.0-dev
v1.27.0-dev
v1.28.0-dev
v28.*
v28.0.0
v29.*
v29.0.0-dev

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86684.json"