Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 07 Oct 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gitea
Gitea gitea |
|
| Vendors & Products |
Gitea
Gitea gitea |
Tue, 06 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Gitea API endpoint `GET /api/v1/repos/{owner}/{repo}/media/{filepath}` wrote files of up to 1 KiB that are stored directly in Git, not in LFS, to the response without the content type and disposition headers Gitea uses for user content. An HTML file committed to a repository was therefore rendered by the browser on the Gitea origin. A user who can push to a repository could run JavaScript in the session of a victim who opens the media URL and act with the victim's permissions. | |
| Title | Gitea repository media API stored XSS | |
| Weaknesses | CWE-79 | |
| References |
|
Status: PUBLISHED
Assigner: Gitea
Published:
Updated: 2026-10-07T15:04:26.695Z
Reserved: 2026-10-04T22:02:04.871Z
Link: CVE-2026-96594
No data.
Status : Awaiting Analysis
Published: 2026-10-06T22:17:07.810
Modified: 2026-10-07T16:19:13.213
Link: CVE-2026-96594
No data.
OpenCVE Enrichment
Updated: 2026-10-07T04:45:11Z