Unrated severityNVD Advisory· Published Oct 6, 2026
CVE-2026-105268
CVE-2026-105268
Description
The Gitea API routes for issue attachments (/api/v1/repos/{owner}/{repo}/issues/{index}/assets/{attachment_id}) also accepted attachments that belong to comments on the issue. Because the author of an issue may edit and delete the issue's attachments, a user who opened an issue could rename or delete attachments that other users had posted in comments on that issue. The contents of the attachments could not be changed.
Affected products
1Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.