---
id: CVE-2026-86684
title: >-
  The Gitea push mirror API checked whether the repository owner, instead of the
  requesting user, may use local file system paths
summary: >-
  The Gitea push mirror API checked whether the repository owner, instead of the
  requesting user, may use local file system paths. On instances with
  `[security] IMPORT_LOCAL_PATHS = true`, a repository administrator who is not
  allowed to i…
severity: none
cwe:
  - CWE-863
vendor: Gitea
product: gitea.dev
affected:
  - gitea.dev >= 1.18.0 <= 28.0.0
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T22:17:07.570'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86684'
references:
  - url: 'https://blog.gitea.com/release-of-28.1.0/'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
  - url: 'https://github.com/go-gitea/gitea/pull/39501'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
  - url: 'https://github.com/go-gitea/gitea/pull/39507'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
  - url: 'https://github.com/go-gitea/gitea/releases/tag/v28.1.0'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
  - url: 'https://github.com/go-gitea/gitea/security/advisories/GHSA-7v5j-mph8-9w6g'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T22:23:15.971Z'
---

## Overview

The Gitea push mirror API checked whether the repository owner, instead of the requesting user, may use local file system paths. On instances with `[security] IMPORT_LOCAL_PATHS = true`, a repository administrator who is not allowed to import local paths could add a push mirror to a local path on the server when the repository owner has that permission. Gitea then pushed the repository's refs into an existing Git repository at that path with the permissions of the Gitea process.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
