{"id":"CVE-2019-1000002","aliases":["GHSA-j99q-rwp6-498g"],"url":"https://o3.security/vulnerability/CVE-2019-1000002","summary":"Gitea Arbitrary File Delete Vulnerability","details":"Gitea version 1.6.2 and earlier contains a Incorrect Access Control vulnerability in Delete/Edit file functionallity that can result in the attacker deleting files outside the repository he/she has access to. This attack appears to be exploitable via the attacker must get write access to \"any\" repository including self-created ones.. This vulnerability appears to have been fixed in 1.6.3, 1.7.0-rc2.","published":"2019-02-04T21:29:00.690Z","modified":"2026-08-07T14:59:45.345082Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"},"epss":{"score":0.01232,"percentile":0.66234,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"code.gitea.io/gitea","fixedVersion":"1.6.3"}],"fix":{"url":"https://github.com/go-gitea/gitea/pull/5631","label":"go-gitea/gitea#5631"},"references":[{"type":"FIX","url":"https://github.com/go-gitea/gitea/pull/5631"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-1000002"},{"type":"PACKAGE","url":"https://github.com/go-gitea/gitea"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:59:45.345082Z"}}