VYPR
Unrated severityNVD Advisory· Published Oct 6, 2026

CVE-2026-94205

CVE-2026-94205

Description

Gitea Actions decided whether a fork pull request run needed approval based on the user who triggered the event rather than the pull request author. For pull_request activity triggered by a maintainer during ordinary triage, such as adding a label, the run was created without requiring approval, while the workflow definition was still taken from the fork head. Where Actions is enabled and a matching runner is registered, fork-controlled workflow code could run on the base repository's runners without an explicit approval.

Affected products

2
  • Go Gitea/Giteareferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.

CVE-2026-94205 · VYPR