← Back to CVE List
Vulnerability Intelligence Report
Gitea fork workflow approval bypass through maintainer-triggered events

CVE-2026-94205

Gitea Actions decided whether a fork pull request run needed approval based on the user who triggered the event rather than the pull request author. For `pull_request` activity triggered by a maintainer during ordinary triage, such as adding a label, the run was created without requiring approval, while the workflow definition was still taken from the fork head. Where Actions is enabled and a matching runner is registered, fork-controlled workflow code could run on the base repository's runners without an explicit approval.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:0.15%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-441 ↗CWE-441: Unintended Proxy or Intermediary ('Confused Deputy')
CWE-863 ↗CWE-863: Incorrect Authorization

Affected Products & Versions

Vendor Product Affected Versions
Gitea Gitea 0 <= 1.27.3 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.148%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitea Limited · Open Source · China
Reserved2026-10-04T21:57:35
Published2026-10-06T19:25:04
Last Updated2026-10-07T20:11:55

LINK COPIED TO CLIPBOARD