
Gitea ghost user (UserID -1) pulls every private container. Middleware never checked package owner. CVE-2026-2777: ReqContainerAccess only tests RequireSignInViewStrict. Ghost sessions enumerate repos, tags, manifests, and layers. Scan + pull PoC is public! Fixed in 1.26.2 https://github.com/portbuster1337/CVE-2026-27771 #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #AppSec #SupplyChain #AuthBypass




