Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

GHSA-j2w3-9c3r-g83q

LowCVSS 2.3 / 10
Published Jul 21, 2026·Last modified Jul 21, 2026
Affected Components(0)

No affected components available

Description

Summary

A user who previously had access to a private repository can continue to obtain repository metadata through GET /api/v1/user/starred after their access to the repository has been revoked.

After a collaborator is removed from a private repository, direct access to the repository is correctly denied. However, the repository may still appear in the user's starred repository list, and the endpoint continues to return repository metadata. Changes made to that metadata after access revocation are also reflected in subsequent responses.

Details

The issue affects the authenticated endpoint:

GET /api/v1/user/starred

The same behavior was also observed on:

GET /api/v1/user/subscriptions

A reproducible scenario is:

  1. User alice creates a private repository.
  2. User bob is granted collaborator access.
  3. bob stars the repository.
  4. alice removes bob from the repository collaborators.
  5. Direct repository access by bob is denied.
  6. bob requests /api/v1/user/starred.
  7. The repository is still present in the response together with repository metadata.

Additionally, if repository metadata is modified after access revocation, the updated values are returned by /api/v1/user/starred.

As a result, a user who no longer has permission to access the repository can continue to obtain repository metadata through the starred repository list.

PoC

PoC Link

https://anonymous.4open.science/r/Gitea_PoC-EC93/5_poc_starred_list

PoC Details

  1. Create a private repository:
alice/P
description = "INITIAL"
  1. Add bob as a collaborator with read access.

  2. As bob, star the repository:

PUT /api/v1/user/starred/alice/P

Response:

204 No Content
  1. Remove bob from the collaborator list.

  2. Update the repository description:

description = "AFTER-REVOKE"
  1. Verify that direct repository access is no longer allowed:
GET /api/v1/repos/alice/P

Response:

404 Not Found
  1. As bob, request the starred repository list:
GET /api/v1/user/starred

The response still contains the repository entry and reflects the updated description:

{
  "full_name": "alice/P",
  "description": "AFTER-REVOKE",
  "private": true
}

This demonstrates that repository metadata remains accessible through the starred repository list even after repository access has been revoked.

Impact

A user who previously had legitimate access to a private repository can continue to retrieve repository metadata after losing access to the repository.

The exposed information includes repository metadata returned by the endpoint, such as:

  • Repository name (full_name)
  • Repository description
  • Repository visibility status (private)

This issue does not expose repository contents, source code, issues, pull requests, secrets, or collaborator information.

The impact is limited to continued access to repository metadata after repository permissions have been revoked.

Risk Scores
Base Score
2.3

The vulnerability can be exploited over the network without needing physical access. It is easy for an attacker to exploit this vulnerability. An attacker needs basic access or low-level privileges. No user interaction is needed for the attacker to exploit this vulnerability.

Threat Intelligence
0.6

Limited exploitation activity has been observed. Close monitoring and planned remediation are recommended.

EPSS
N/A

Probability that this vulnerability will be exploited in the wild within the next 30 days.

Exploit
Not available

We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.

Related Vulnerabilities
  • CVE-2026-58434
    Alias

Browse More

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard