{"id":"CVE-2026-58438","aliases":["GHSA-xv9x-fj9g-vj6h"],"title":"Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access","summary":"Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access","severity":"low","cwe":["CWE-862"],"vendor":"gitea.dev","product":"gitea.dev","ecosystem":"go","affected":["gitea.dev < 1.27.0"],"patched":["gitea.dev 1.27.0"],"published":"2026-07-21","updated":"2026-07-21","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-xv9x-fj9g-vj6h","references":[{"url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-xv9x-fj9g-vj6h"},{"url":"https://github.com/go-gitea/gitea/releases/tag/v1.27.0"},{"url":"https://github.com/advisories/GHSA-xv9x-fj9g-vj6h"}],"tags":["ghsa","go"],"ingestedAt":"2026-07-21T20:54:26.922Z","epss":0.00268,"epssPercentile":0.19144,"slug":"CVE-2026-58438","body":"## Overview\n\n### Details\n`RemoveDependency` in `routers/web/repo/issue_dependency.go` takes a `removeDependencyID` form parameter identifying the other issue by its global numeric ID, and fetches it with `issues_model.GetIssueByID(ctx, depID)` - no repository or permission check at all. It then calls `issues_model.RemoveIssueDependency(ctx, ctx.Doer, issue, dep, depType)` (`models/issues/dependency.go`), which deletes the dependency join row and then writes a comment referencing the removal, attributed to the calling user, onto the dependency record.\n\nThe sibling function in the very same file, `AddDependency`, does this correctly when the two issues are in different repos (which `ALLOW_CROSS_REPOSITORY_DEPENDENCIES`, on by default, permits):\n\n```go\nif issue.RepoID != dep.RepoID {\n  if !setting.Service.AllowCrossRepositoryDependencies { ... }\n  depRepoPerm, err := access_model.GetDoerRepoPermission(ctx, dep.Repo, ctx.Doer)\n  if !depRepoPerm.CanReadIssuesOrPulls(dep.IsPull) {\n    return // you can't see this dependency\n  }\n}\n```\n\n`RemoveDependency` has no equivalent block at all - it goes straight from resolving `dep` by ID to deleting the link, regardless of which repo `dep` lives in or whether the caller can see it. I confirmed this same code is present in the current latest release, v1.26.4.\n\n### PoC\nPrerequisites: an account with write access to issues on some repo `ownerA/repoA`, and the global numeric issue ID of an issue in a private repo `repoB` that is (or was) legitimately dependency-linked to one of the attacker's issues in `repoA` (cross-repo dependencies are commonly used between related public/private repos, and `ALLOW_CROSS_REPOSITORY_DEPENDENCIES` defaults to enabled).\n\n```bash\ncurl -s -b \"gitea_session=$ATTACKER_SESSION_COOKIE\" -X POST \\\n  --data-urlencode \"removeDependencyID=<repoB_issue_global_id>\" \\\n  --data-urlencode \"dependencyType=blockedBy\" \\\n  \"https://TARGET_HOST/ownerA/repoA/issues/N/dependency/delete\"\n# Expected: the dependency link is deleted and a \"removed dependency\" comment\n# authored by the attacker is added to the repoB issue, even though the\n# attacker has no read access to repoB.\n```\n\n### Impact\nThis is a cross-repository IDOR / broken access control issue. An attacker can tamper with issue-tracking state (dependency relationships) and inject an attacker-authored comment into a private repository they cannot otherwise read or write to, crossing a trust boundary the \"add\" path explicitly enforces. Impact is bounded - it requires an existing dependency link and discloses no repository content - but it is a genuine unauthorized-write primitive across a private-repo boundary.\n\n### Fix\nAdd the same cross-repo permission check used in `AddDependency` (`access_model.GetDoerRepoPermission(ctx, dep.Repo, ctx.Doer).CanReadIssuesOrPulls(dep.IsPull)`) to `RemoveDependency` before allowing the deletion to proceed when `issue.RepoID != dep.RepoID`.\n\n**If possible, please apply for a CVE number when publishing. I would greatly appreciate it.**\n\n## Affected packages\n\n- `gitea.dev < 1.27.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `gitea.dev 1.27.0`","depth":"sunlit","depthScore":14,"depthScoreParts":{"impact":13.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}