CVE-2026-86684
Beschrijving NL
De Gitea push mirror API controleerde of de eigenaar van de repository, in plaats van de verzoekende gebruiker, lokale bestandssysteempaden mag gebruiken. Op instanties met `[security] IMPORT_LOCAL_PATHS = true` kan een beheerder van een repository die geen toestemming heeft om lokale paden te importeren een push mirror toevoegen aan een lokaal pad op de server wanneer de eigenaar van de repository die toestemming heeft. Gitea pushte vervolgens de referenties van de repository naar een bestaande Git-repository op dat pad met de machtigingen van het Gitea-proces.
Origineel (Engels) tonen
The Gitea push mirror API checked whether the repository owner, instead of the requesting user, may use local file system paths. On instances with `[security] IMPORT_LOCAL_PATHS = true`, a repository administrator who is not allowed to import local paths could add a push mirror to a local path on the server when the repository owner has that permission. Gitea then pushed the repository's refs into an existing Git repository at that path with the permissions of the Gitea process.