๐Ÿ” CVE Alert

CVE-2026-96594

UNKNOWN 0.0

Gitea repository media API stored XSS

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Gitea API endpoint `GET /api/v1/repos/{owner}/{repo}/media/{filepath}` wrote files of up to 1 KiB that are stored directly in Git, not in LFS, to the response without the content type and disposition headers Gitea uses for user content. An HTML file committed to a repository was therefore rendered by the browser on the Gitea origin. A user who can push to a repository could run JavaScript in the session of a victim who opens the media URL and act with the victim's permissions.

CWE CWE-79
Vendor gitea
Product gitea
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for gitea gitea

Be the first to know when new unknown vulnerabilities affecting gitea gitea are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Gitea / Gitea
0 โ‰ค 28.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/go-gitea/gitea/security/advisories/GHSA-94rx-fqm6-q23v github.com: https://github.com/go-gitea/gitea/pull/39501 github.com: https://github.com/go-gitea/gitea/pull/39507 blog.gitea.com: https://blog.gitea.com/release-of-28.1.0/ github.com: https://github.com/go-gitea/gitea/releases/tag/v28.1.0

Credits

๐Ÿ” https://github.com/KadirArslan ๐Ÿ” https://github.com/cruzzer https://github.com/silverwind https://github.com/bircni