CVE-2026-94205

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Gitea Actions decided whether a fork pull request run needed approval based on the user who triggered the event rather than the pull request author. For `pull_request` activity triggered by a maintainer during ordinary triage, such as adding a label, the run was created without requiring approval, while the workflow definition was still taken from the fork head. Where Actions is enabled and a matching runner is registered, fork-controlled workflow code could run on the base repository's runners without an explicit approval.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-441CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-10-08: 210-08
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Atlas Threat Monitoring@ThreatAtlas

    Unpatched vulnerabilities don't stay hidden on our atlas. #CVE CRITICAL VULNERABILITY DETECTED CVE ID → CVE-2026-94205 Vendor → Unknown Severity → Critical — CVSS 9.8 Product → Unknown Date → 2026-10-06 A critical vulnerability (Confused Deputy) has been disclosed affecting Unknown. Patch immediately. Powered by @Brandefense #ThreatIntel #CyberSecurity #CVE #Unknown

    0000039
    451 followersView on X
  • The Hacker Wire@TheHackerWire

    🚨 CVE-2026-94205 (CVSS 9.8 Critical)Flaw in Gitea Actions allows fork pull request workflows to run automatically on base repository runners during triage, enabling unauthenticated arbitrary code execution.https://www.thehackerwire.com/vulnerability/CVE-2026-94205/ https://t.co/fxzZeDqXI3

    0000042
    176 followersView on X

Explore more