Intel

AIKIDO-2026-10383

code.gitea.io/gitea is vulnerable to Improper Access Control

Improper Access Control Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Mar 18, 2026

39

Low Risk

This Affects:

GOcode.gitea.io/gitea
0.0.1 - 1.25.4
Fixed in 1.25.5
Are you affected? Scan for Free

TL;DR

The patched version of this package includes minor security hardening fixes addressing edge cases in request handling and permission checks. The release improves validation and access control logic to prevent unintended behavior in scenarios involving user visibility and resource access, reducing the risk of information exposure or authorization inconsistencies. Additionally, fixes to request processing and input handling help mitigate potential denial-of-service conditions triggered by malformed or unexpected input. These changes collectively strengthen the robustness of the application against low-impact security issues.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

code.gitea.io/gitea is vulnerable to Improper Access Control in versions 0.0.1 - 1.25.4.

How to fix this

Upgrade the code.gitea.io/gitea library to the patch version.