OSV 1.4.0 · github-reviewed · 修改于 2026-06-17 07:41
发布时间
2026-06-17 07:41
GitHub 审查时间
2026-06-17 07:41
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/06/GHSA-mm7c-rhg6-qr4r/GHSA-mm7c-rhg6-qr4r.json
Any authenticated low-privilege user with read access to a repository can push arbitrary commits directly to that repository, bypassing all write-access checks.
Gitea's "Allow edits from maintainers" PR option can be abused via reverse-fork PRs:
allow_maintainer_edit=true without verifying that the submitter has write access to the HEAD repository.git push over HTTP/SSH, Gitea relaxes the required access mode to Read when SupportProcReceive is enabled (routers/web/repo/githttp.go, routers/private/serv.go) and defers enforcement to the pre-receive hook.CanMaintainerWriteToBranch (models/issues/pull_list.go), which finds the malicious PR, sees AllowMaintainerEdit=true, and checks whether the pusher has write access to the BASE repo. Since BASE is the attacker's own fork, the check passes and the push is authorized against the upstream.BASE = their_fork, HEAD = upstream, and "Allow edits from maintainers" checked.git push <upstream_url> <branch> — the push is accepted.python3 poc.py --repo http://gitea:3000/victim/repo --user attacker --password attacker_pass
Expected output:
[+] target: victim/my_repo default branch: main
[*] forking -> attacker/my_repo_pocfork (202)
[+] fork ready
[+] malicious PR created (BASE=attacker fork, HEAD=upstream)
remote: . Processing 1 references
remote: Processed 1 references in total
To http://192.168.101.20:3000/victim/my_repo.git
e5c07b3..9a0b884 main -> main
[+] latest commit on victim/my_repo@main: 'PoC: unauthorized commit via maintainer-edit bypass'
[+] CONFIRMED: unauthorized push to upstream succeeded.
A PWNED.txt file will appear on the target repo's default branch, committed by the attacker who has no write access.
Full repository compromise. Any logged-in user can backdoor any repository they can read, including all public repositories on the instance.
Two independent checks are missing; both should be added for defense in depth:
AllowMaintainerEdit = true, verify the submitter has write access to the HEAD repository.CanMaintainerWriteToBranch: verify that the PR's HEAD repo matches the repository being pushed to, and that the PR was opened by a legitimate owner/writer of the HEAD repository. Do not trust AllowMaintainerEdit solely based on BASE write access.