CVE-2026-89182mediumCWE-863

CVE-2026-89182: medium-severity vulnerability in Gitea

Gitea push-to-create bypass of FORCE_PRIVATE policy

Published · Updated

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.4epss 0.1%
exploitation probability
0.1%top 97% of all CVEs
observed exploitation
nono source reports it
With `[repository] FORCE_PRIVATE = true`, Gitea creates new repositories as private, but the post-receive hook still applied the `repo.private=false` push option to an empty repository created by push. Any user who can create repositories could make their new repository public in violation of the instance policy. The default configuration is not affected.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Affected products
Gitea · Gitea