{"id":"CVE-2026-58438","aliases":["GHSA-xv9x-fj9g-vj6h","GO-2026-6085"],"url":"https://o3.security/vulnerability/CVE-2026-58438","summary":"Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access","details":"### Details\n`RemoveDependency` in `routers/web/repo/issue_dependency.go` takes a `removeDependencyID` form parameter identifying the other issue by its global numeric ID, and fetches it with `issues_model.GetIssueByID(ctx, depID)` - no repository or permission check at all. It then calls `issues_model.RemoveIssueDependency(ctx, ctx.Doer, issue, dep, depType)` (`models/issues/dependency.go`), which deletes the dependency join row and then writes a comment referencing the removal, attributed to the calling user, onto the dependency record.\n\nThe sibling function in the very same file, `AddDependency`, does this correctly when the two issues are in different repos (which `ALLOW_CROSS_REPOSITORY_DEPENDENCIES`, on by default, permits):\n\n```go\nif issue.RepoID != dep.RepoID {\n  if !setting.Service.AllowCrossRepositoryDependencies { ... }\n  depRepoPerm, err := access_model.GetDoerRepoPermission(ctx, dep.Repo, ctx.Doer)\n  if !depRepoPerm.CanReadIssuesOrPulls(dep.IsPull) {\n    return // you can't see this dependency\n  }\n}\n```\n\n`RemoveDependency` has no equivalent block at all - it goes straight from resolving `dep` by ID to deleting the link, regardless of which repo `dep` lives in or whether the caller can see it. I confirmed this same code is present in the current latest release, v1.26.4.\n\n### PoC\nPrerequisites: an account with write access to issues on some repo `ownerA/repoA`, and the global numeric issue ID of an issue in a private repo `repoB` that is (or was) legitimately dependency-linked to one of the attacker's issues in `repoA` (cross-repo dependencies are commonly used between related public/private repos, and `ALLOW_CROSS_REPOSITORY_DEPENDENCIES` defaults to enabled).\n\n```bash\ncurl -s -b \"gitea_session=$ATTACKER_SESSION_COOKIE\" -X POST \\\n  --data-urlencode \"removeDependencyID=<repoB_issue_global_id>\" \\\n  --data-urlencode \"dependencyType=blockedBy\" \\\n  \"https://TARGET_HOST/ownerA/repoA/issues/N/dependency/delete\"\n# Expected: the dependency link is deleted and a \"removed dependency\" comment\n# authored by the attacker is added to the repoB issue, even though the\n# attacker has no read access to repoB.\n```\n\n### Impact\nThis is a cross-repository IDOR / broken access control issue. An attacker can tamper with issue-tracking state (dependency relationships) and inject an attacker-authored comment into a private repository they cannot otherwise read or write to, crossing a trust boundary the \"add\" path explicitly enforces. Impact is bounded - it requires an existing dependency link and discloses no repository content - but it is a genuine unauthorized-write primitive across a private-repo boundary.\n\n### Fix\nAdd the same cross-repo permission check used in `AddDependency` (`access_model.GetDoerRepoPermission(ctx, dep.Repo, ctx.Doer).CanReadIssuesOrPulls(dep.IsPull)`) to `RemoveDependency` before allowing the deletion to proceed when `issue.RepoID != dep.RepoID`.\n\n**If possible, please apply for a CVE number when publishing. I would greatly appreciate it.**","published":"2026-08-13T16:44:53.141Z","modified":"2026-08-28T11:30:56.280835046Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.00268,"percentile":0.19077,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"gitea.dev","fixedVersion":"1.27.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://blog.gitea.com/gitea-1.27.0-is-released/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58438.json"},{"type":"ADVISORY","url":"https://github.com/go-gitea/gitea/releases/tag/v1.27.0"},{"type":"ADVISORY","url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-xv9x-fj9g-vj6h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58438"},{"type":"PACKAGE","url":"https://github.com/go-gitea/gitea"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-28T11:30:56.280835046Z"}}