FixVibe

// 코드 / 스포트라이트

Gitea Composer Source-Link Permission Advisory

Pinned affected Gitea server images need a deployment upgrade.

What it is

Self-hosted Git services hold source code and package metadata near high-trust developer workflows. When an affected Gitea version appears in deployment configuration, maintainers get a concrete upgrade signal without an intrusive authorization test.

How it happens

CVE-2026-27771 is a missing permission check around Composer package source links in Gitea releases through 1.26.1, fixed in 1.26.2. Gitea's package registry can link a Composer package to a source repository, and affected releases hand out that link without checking whether the caller may see the linked repository.

What an attacker gets

A caller who can read a Composer package may receive source-location information for a linked repository they cannot otherwise access, which can reveal the names and locations of private or internal repositories.

// what fixvibe reports

What FixVibe reports

Runs when you connect a GitHub repository, on Pro and above. Each finding shows the file and line, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Upgrade every active Gitea server deployment to 1.26.2 or newer, preferably the latest supported release, then rebuild or redeploy and verify the running version. Review Composer package visibility and linked-repository permissions through normal authorized administration after the upgrade.

// 내 앱에서 직접 실행해보세요

FixVibe가 지켜보는 동안 계속 배포하세요.

Connect a GitHub repo to check its code, dependencies and workflows.

소스 코드
198
이 카테고리에서 실행되는 테스트
모듈
155
전용 소스 코드 검사
GitHub repos
190+
checks on each connected repo
Connect GitHub →

// 최신 체크 · 실용적인 수정 · 자신 있게 배포

Gitea Composer Source-Link Permission Advisory: what it is and how to fix it · FixVibe