HIGH7.5
GHSA-37w2-86g3-h4qh
Gitea organization permission APIs expose hidden membership and private organization data
Quick fix
GHSA-37w2-86g3-h4qh — code.gitea.io/gitea: upgrade to the fixed version with the command below.
go get code.gitea.io/gitea@v1.25.5Details
Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-25712[ADVISORY]
- https://github.com/go-gitea/gitea/pull/36798[WEB]
- https://github.com/go-gitea/gitea/pull/36841[WEB]
- https://github.com/go-gitea/gitea/commit/57b5ed3f252753797e790c060c42fbbe8219b9c1[WEB]
- https://github.com/go-gitea/gitea/commit/96515c0f200d37228dc84a599c6177297a230c94[WEB]
- https://blog.gitea.com/release-of-1.25.5[WEB]
- https://github.com/go-gitea/gitea[PACKAGE]
- https://github.com/go-gitea/gitea/releases/tag/v1.25.5[WEB]