CVE-2026-89182 PUBLISHED

Gitea push-to-create bypass of FORCE_PRIVATE policy

Assigner: Gitea
Reserved: 04.10.2026 Published: 06.10.2026 Updated: 07.10.2026

With [repository] FORCE_PRIVATE = true, Gitea creates new repositories as private, but the post-receive hook still applied the repo.private=false push option to an empty repository created by push. Any user who can create repositories could make their new repository public in violation of the instance policy. The default configuration is not affected.

Product Status

Vendor Gitea
Product Gitea
Versions Default: unaffected
  • affected from 1.27.0 to 28.0.0 (incl.)

Credits

  • https://github.com/manus-pi reporter
  • https://github.com/silverwind remediation developer
  • https://github.com/bircni remediation developer

References

Problem Types

  • CWE-863: Incorrect Authorization CWE