Gitea Vulnerability: Cached Permission Check Allows Full Write Access
An early warning has been issued regarding a vulnerability in Gitea version 1.25.5 that reportedly allows full repository write access due to cached per-branch permission checks in the pre-receive hook.
What happened
Gitea version 1.25.5 is under investigation for a high-severity vulnerability tracked as GHSA-649p-mmhf-85c7. This vulnerability appears to allow an authorization bypass, enabling full write access to repositories. The issue stems from cached per-branch permission checks within the pre-receive hook, which may not correctly enforce access controls. Professional software engineers using this version should assess their exposure and consider upgrading to a patched version as recommended by the advisory. For detailed information, consult the primary source at https://github.com/go-gitea/gitea/security/advisories/GHSA-649p-mmhf-85c7.
How 0Day mitigates this
gitea is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.