GHSA-rh79-75qm-gwjr: Gitea LFS Deploy-Key Privilege Escalation
mediumvulnerability
security
Summary
Gitea has a privilege escalation vulnerability in its LFS (Large File Storage, a Git extension for handling large files) server where deploy keys (limited-access credentials for CI/CD systems) can be used to impersonate the repository owner. The bug occurs because when authenticating via deploy key, the system sets the user ID in the JWT (a signed token used to verify identity) to the repository owner's ID instead of a unique deploy key identifier, allowing an attacker with a write deploy key to access LFS objects from any private repository owned by the victim.
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.0%
Patch Available
Yes
Disclosure Date
July 21, 2026
Classification
Attack SophisticationModerate
Affected Packages
code.gitea.io/gitea@< 1.27.0 (fixed: 1.27.0)
Monthly digest — independent AI security research
Original source: https://github.com/advisories/GHSA-rh79-75qm-gwjr
First tracked: July 21, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 95%