All CVEs View on NVD
CVE-2026-94205
CRITICAL9.8
Published 2026-10-06 · Updated 2026-10-07 · Source 88ee5874-cf24-4952-aea0-31affedb7ff2
Description
Gitea Actions decided whether a fork pull request run needed approval based on the user who triggered the event rather than the pull request author. For `pull_request` activity triggered by a maintainer during ordinary triage, such as adding a label, the run was created without requiring approval, while the workflow definition was still taken from the fork head. Where Actions is enabled and a matching runner is registered, fork-controlled workflow code could run on the base repository's runners without an explicit approval.
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-441CWE-863

