{"id":"CVE-2026-96594","title":"The Gitea API endpoint `GET /api/v1/repos/{owner}/{repo}/media/{filepath}` wrote files of up to 1 KiB that are stored directly in Git, not in LFS, to the response without the content type and disposition headers Gitea uses for user conte…","summary":"The Gitea API endpoint `GET /api/v1/repos/{owner}/{repo}/media/{filepath}` wrote files of up to 1 KiB that are stored directly in Git, not in LFS, to the response without the content type and disposition headers Gitea uses for user conte…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"Gitea","product":"gitea.dev","affected":["gitea.dev <= 28.0.0"],"published":"2026-10-06","updated":"2026-10-07","sourceUpdated":"2026-10-07T16:19:13.213","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-96594","references":[{"url":"https://blog.gitea.com/release-of-28.1.0/","label":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/pull/39501","label":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/pull/39507","label":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/releases/tag/v28.1.0","label":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-94rx-fqm6-q23v","label":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-96594.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-96594"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-96594"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-07T15:04:06.630412Z"},"scores":{"nvd":6.1,"vendor":5.4,"adp":6.1},"ingestedAt":"2026-10-06T22:23:15.972Z","slug":"CVE-2026-96594","body":"## Overview\n\nThe Gitea API endpoint `GET /api/v1/repos/{owner}/{repo}/media/{filepath}` wrote files of up to 1 KiB that are stored directly in Git, not in LFS, to the response without the content type and disposition headers Gitea uses for user content. An HTML file committed to a repository was therefore rendered by the browser on the Gitea origin. A user who can push to a repository could run JavaScript in the session of a victim who opens the media URL and act with the victim's permissions.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · updated 2026-10-07 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-96594.json)","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":217616,"id":"CVE-2026-96594","ts":1791391165609,"field":"cvss","old":"5.4","new":"6.1"},{"seq":217097,"id":"CVE-2026-96594","ts":1791360682134,"field":"cvss","old":null,"new":"5.4"},{"seq":217096,"id":"CVE-2026-96594","ts":1791360682134,"field":"severity","old":"none","new":"medium"}]}