UNKNOWN Go

Gitea does not properly validate repository ownership when deleting Git LFS locks

GHSA-393c-qgvj-3xph · BIT-gitea-2026-20897 · CVE-2026-20897 · GHSA-rrq5-r9h5-pc7c · GO-2026-4363

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories.

Ready to move

Start Securing

Free, no credit card | First findings in minutes