FixVibe

// code / spotlight

Gitea Composer Source-Link Permission Advisory

Pinned affected Gitea server images need a deployment upgrade.

The hook

Self-hosted Git services hold source code and package metadata near high-trust developer workflows. When an affected Gitea version appears in deployment configuration, maintainers get a concrete upgrade signal without an intrusive authorization test.

How it works

The advisory concerns permission checks around Composer package source links in Gitea releases through 1.26.1. A repository match establishes the pinned server image version only; deployment, Composer registry use, linked-repository visibility, caller access, and actual disclosure remain unverified.

The blast radius

Under the advisory conditions, a caller who can read a Composer package may receive source-location information for a linked repository they cannot otherwise access. That can reveal private or internal repository metadata, but a repo version match alone does not establish those runtime conditions.

// what fixvibe checks

What FixVibe checks

FixVibe repo scans look for high-confidence security patterns and dependency risk in source context. Reports identify the affected area and recommended fix. For check-specific questions about exact detection heuristics, active payload details, or source-code rule patterns, contact support@fixvibe.app.

Ironclad defenses

Upgrade every active Gitea server deployment to 1.26.2 or newer, preferably the latest supported release, then rebuild or redeploy and verify the running version. Review Composer package visibility and linked-repository permissions through normal authorized administration after the upgrade.

// run it on your own app

Keep shipping while FixVibe keeps watch.

FixVibe pressure-tests the public surface of your app the way an attacker would β€” no agent, no install, no card. We keep researching new vulnerability patterns and turn them into practical checks and paste-ready fixes for Cursor, Claude, and Copilot.

Source code
160
tests fired in this category
modules
120
dedicated source code checks
every scan
540+
tests across all categories
  • Free β€” no credit card, no install, no Slack ping
  • Just paste a URL β€” we crawl, probe, and report
  • Severity-graded findings, deduped to signal only
  • AI-ready prompts where code applies, plus operator steps for DNS/provider fixes
Run a free scan β†’

// latest checks Β· practical fixes Β· ship with confidence

Gitea Composer Source-Link Permission Advisory β€” Vulnerability Spotlight | FixVibe Β· FixVibe