CVE-2026-105268 PUBLISHED

Gitea issue attachment API allows changing comment attachments

Assigner: Gitea
Reserved: 04.10.2026 Published: 06.10.2026 Updated: 06.10.2026

The Gitea API routes for issue attachments (/api/v1/repos/{owner}/{repo}/issues/{index}/assets/{attachment_id}) also accepted attachments that belong to comments on the issue. Because the author of an issue may edit and delete the issue's attachments, a user who opened an issue could rename or delete attachments that other users had posted in comments on that issue. The contents of the attachments could not be changed.

Product Status

Vendor Gitea
Product Gitea
Versions Default: unaffected
  • affected from 0 to 28.0.0 (incl.)

Credits

  • https://github.com/N0K0 reporter
  • https://github.com/silverwind remediation developer
  • https://github.com/bircni remediation developer

References

Problem Types

  • CWE-639: Authorization Bypass Through User-Controlled Key CWE
  • CWE-863: Incorrect Authorization CWE