Intel

AIKIDO-2025-10757

code.gitea.io/gitea is vulnerable to Improper Access Control

Improper Access Control Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 31, 2025

68

Medium Risk

This Affects:

GOcode.gitea.io/gitea
1.22.0 - 1.24.6
Fixed in 1.24.7
Are you affected? Scan for Free

TL;DR

Affected versions of this package allow an attacker to bypass Git LFS authorization or exploit symlinks to access files outside their container or repository path. The patch enforces correct authorization for LFS requests and blocks symlink misresolution that could lead to unintended file access.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

code.gitea.io/gitea is vulnerable to Improper Access Control in versions 1.22.0 - 1.24.6.

How to fix this

Upgrade the code.gitea.io/gitea library to the patch version.