UNKNOWN Go

Gitea does not properly validate project ownership in organization project operations

GHSA-rw22-5hhq-pfpf · BIT-gitea-2026-20750 · CVE-2026-20750 · GHSA-h4fh-pc4w-8w27 · GO-2026-4370

Published · Modified

Description

Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization.

Ready to move

Start Securing

Free, no credit card | First findings in minutes