VYPR
High severity8.5GHSA Advisory· Published Jul 3, 2026· Updated Jul 7, 2026

CVE-2026-26231

CVE-2026-26231

Description

Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
code.gitea.io/giteaGo
< 1.26.21.26.2

Affected products

2

Patches

Vulnerability mechanics

References

6

News mentions

1