{"schema_version":"1.9.0","id":"GHSA-xv9x-fj9g-vj6h","published":"2026-07-21T20:36:59Z","modified":"2026-07-27T17:11:41.902564853Z","aliases":["CVE-2026-58438","GO-2026-6085"],"summary":"Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access","details":"### Details\n`RemoveDependency` in `routers/web/repo/issue_dependency.go` takes a `removeDependencyID` form parameter identifying the other issue by its global numeric ID, and fetches it with `issues_model.GetIssueByID(ctx, depID)` - no repository or permission check at all. It then calls `issues_model.RemoveIssueDependency(ctx, ctx.Doer, issue, dep, depType)` (`models/issues/dependency.go`), which deletes the dependency join row and then writes a comment referencing the removal, attributed to the calling user, onto the dependency record.\n\nThe sibling function in the very same file, `AddDependency`, does this correctly when the two issues are in different repos (which `ALLOW_CROSS_REPOSITORY_DEPENDENCIES`, on by default, permits):\n\n```go\nif issue.RepoID != dep.RepoID {\n  if !setting.Service.AllowCrossRepositoryDependencies { ... }\n  depRepoPerm, err := access_model.GetDoerRepoPermission(ctx, dep.Repo, ctx.Doer)\n  if !depRepoPerm.CanReadIssuesOrPulls(dep.IsPull) {\n    return // you can't see this dependency\n  }\n}\n```\n\n`RemoveDependency` has no equivalent block at all - it goes straight from resolving `dep` by ID to deleting the link, regardless of which repo `dep` lives in or whether the caller can see it. I confirmed this same code is present in the current latest release, v1.26.4.\n\n### PoC\nPrerequisites: an account with write access to issues on some repo `ownerA/repoA`, and the global numeric issue ID of an issue in a private repo `repoB` that is (or was) legitimately dependency-linked to one of the attacker's issues in `repoA` (cross-repo dependencies are commonly used between related public/private repos, and `ALLOW_CROSS_REPOSITORY_DEPENDENCIES` defaults to enabled).\n\n```bash\ncurl -s -b \"gitea_session=$ATTACKER_SESSION_COOKIE\" -X POST \\\n  --data-urlencode \"removeDependencyID=<repoB_issue_global_id>\" \\\n  --data-urlencode \"dependencyType=blockedBy\" \\\n  \"https://TARGET_HOST/ownerA/repoA/issues/N/dependency/delete\"\n# Expected: the dependency link is deleted and a \"removed dependency\" comment\n# authored by the attacker is added to the repoB issue, even though the\n# attacker has no read access to repoB.\n```\n\n### Impact\nThis is a cross-repository IDOR / broken access control issue. An attacker can tamper with issue-tracking state (dependency relationships) and inject an attacker-authored comment into a private repository they cannot otherwise read or write to, crossing a trust boundary the \"add\" path explicitly enforces. Impact is bounded - it requires an existing dependency link and discloses no repository content - but it is a genuine unauthorized-write primitive across a private-repo boundary.\n\n### Fix\nAdd the same cross-repo permission check used in `AddDependency` (`access_model.GetDoerRepoPermission(ctx, dep.Repo, ctx.Doer).CanReadIssuesOrPulls(dep.IsPull)`) to `RemoveDependency` before allowing the deletion to proceed when `issue.RepoID != dep.RepoID`.\n\n**If possible, please apply for a CVE number when publishing. I would greatly appreciate it.**","affected":[{"package":{"name":"gitea.dev","ecosystem":"Go","purl":"pkg:golang/gitea.dev"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.27.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-xv9x-fj9g-vj6h/GHSA-xv9x-fj9g-vj6h.json"}}],"references":[{"type":"WEB","url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-xv9x-fj9g-vj6h"},{"type":"PACKAGE","url":"https://github.com/go-gitea/gitea"},{"type":"WEB","url":"https://github.com/go-gitea/gitea/releases/tag/v1.27.0"}],"database_specific":{"cwe_ids":["CWE-862"],"github_reviewed":true,"github_reviewed_at":"2026-07-21T20:36:59Z","nvd_published_at":null,"severity":"LOW"},"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N"}]}