VYPR
Unrated severityNVD Advisory· Published Oct 6, 2026

CVE-2026-105268

CVE-2026-105268

Description

The Gitea API routes for issue attachments (/api/v1/repos/{owner}/{repo}/issues/{index}/assets/{attachment_id}) also accepted attachments that belong to comments on the issue. Because the author of an issue may edit and delete the issue's attachments, a user who opened an issue could rename or delete attachments that other users had posted in comments on that issue. The contents of the attachments could not be changed.

Affected products

1

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.

CVE-2026-105268 · VYPR