{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-96594","assignerOrgId":"88ee5874-cf24-4952-aea0-31affedb7ff2","state":"PUBLISHED","assignerShortName":"Gitea","dateReserved":"2026-10-04T22:02:04.871Z","datePublished":"2026-10-06T21:36:38.491Z","dateUpdated":"2026-10-06T21:36:38.491Z"},"containers":{"cna":{"providerMetadata":{"orgId":"88ee5874-cf24-4952-aea0-31affedb7ff2","shortName":"Gitea","dateUpdated":"2026-10-06T21:36:38.491Z"},"title":"Gitea repository media API stored XSS","descriptions":[{"lang":"en","value":"The Gitea API endpoint `GET /api/v1/repos/{owner}/{repo}/media/{filepath}` wrote files of up to 1 KiB that are stored directly in Git, not in LFS, to the response without the content type and disposition headers Gitea uses for user content. An HTML file committed to a repository was therefore rendered by the browser on the Gitea origin. A user who can push to a repository could run JavaScript in the session of a victim who opens the media URL and act with the victim's permissions."}],"affected":[{"vendor":"Gitea","product":"Gitea","packageName":"gitea.dev","defaultStatus":"unaffected","versions":[{"version":"0","status":"affected","lessThanOrEqual":"28.0.0","versionType":"semver"}]}],"references":[{"url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-94rx-fqm6-q23v","name":"GitHub Security Advisory GHSA-94rx-fqm6-q23v","tags":["vendor-advisory"]},{"url":"https://github.com/go-gitea/gitea/pull/39501","name":"Fix: go-gitea/gitea pull request #39501","tags":["patch"]},{"url":"https://github.com/go-gitea/gitea/pull/39507","name":"Fix backport to release/v28: go-gitea/gitea pull request #39507","tags":["patch"]},{"url":"https://blog.gitea.com/release-of-28.1.0/","name":"Gitea 28.1.0 release announcement","tags":["release-notes"]},{"url":"https://github.com/go-gitea/gitea/releases/tag/v28.1.0","name":"go-gitea/gitea v28.1.0 release","tags":["release-notes"]}],"problemTypes":[{"descriptions":[{"lang":"en","type":"CWE","cweId":"CWE-79","description":"CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"}]}],"credits":[{"lang":"en","value":"https://github.com/KadirArslan","type":"reporter"},{"lang":"en","value":"https://github.com/cruzzer","type":"reporter"},{"lang":"en","value":"https://github.com/silverwind","type":"remediation developer"},{"lang":"en","value":"https://github.com/bircni","type":"remediation developer"}]}}}