CVE-2026-94205: Gitea

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Gitea Actions decided whether a fork pull request run needed approval based on the user who triggered the event rather than the pull request author. For `pull_request` activity triggered by a maintainer during ordinary triage, such as adding a label, the run was created without requiring approval, while the workflow definition was still taken from the fork head. Where Actions is enabled and a matching runner is registered, fork-controlled workflow code could run on the base repository's runners without an explicit approval.

Affected products

  • Gitea Gitea: up to and including 1.27.3

Published 2026-10-06. Last modified 2026-10-07.