HackerFeeds
All CVEs

CVE-2026-94205

CRITICAL9.8

Published 2026-10-06 · Updated 2026-10-07 · Source 88ee5874-cf24-4952-aea0-31affedb7ff2

Description

Gitea Actions decided whether a fork pull request run needed approval based on the user who triggered the event rather than the pull request author. For `pull_request` activity triggered by a maintainer during ordinary triage, such as adding a label, the run was created without requiring approval, while the workflow definition was still taken from the fork head. Where Actions is enabled and a matching runner is registered, fork-controlled workflow code could run on the base repository's runners without an explicit approval.

CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CWE-441CWE-863
View on NVD