A vulnerability in Gitea Actions (versions v1.20.0 and later) allows an unprivileged attacker to permanently bypass the fork pull request approval gate for a repository after a single, initial workflow approval, enabling arbitrary shell command execution on the Gitea Actions runner without further maintainer interaction, leading to source code disclosure and potential system compromise.
PoC
Gitea +1
logic-bug
ci-cd
code-execution
privilege-escalation
gitea-actions
4t
1c
1i
updated