Gitea Private Project Access Vulnerability for Anonymous Users

Vulnerability

A vulnerability in Gitea versions prior to 1.21.2 allows anonymous users to access private projects of other users. This issue arises from insufficient permission checks, which were addressed in the 1.21.2 release.

Impact

Exploitation of this vulnerability allows anonymous users to view private projects, potentially leading to unauthorized access to sensitive information or project details.

Remediation

Users are advised to upgrade to Gitea version 1.21.2 or later, where this vulnerability has been fixed.

Added: Dec 26, 2025, 4:18 AM
Updated: Dec 26, 2025, 4:18 AM

Vulnerability Rating

Custom Algorithm
spread
7.6
impact
2.5
exploitability
7.6
remediation
7.7
relevance
1.6
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.