CVE-2022-30781 is a remote command execution vulnerability in Gitea prior to version 1.16.7. The flaw exists in the repository migration feature, where attacker-controlled fields from a migration API response are unsafely incorporated into Git command arguments. Specifically, the '--upload-pack' parameter in 'git fetch' can be manipulated to execute arbitrary shell commands on the target Gitea server. The vulnerability is triggered during the migration of pull request data from a malicious Gitea instance, allowing the attacker to inject parameters into Git commands executed by the target server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit module (Ruby file) that exploits a remote code execution vulnerability (CVE-2022-30781) in Gitea versions prior to 1.16.7. The exploit leverages the repository migration feature in Gitea, which uses the 'git fetch' command, to achieve arbitrary command execution on the server. The module supports multiple platforms (Linux, Unix, Windows) and can deliver a variety of payloads, including reverse shells and Meterpreter sessions, using Metasploit's payload system. The exploit requires valid Gitea credentials and network access to the Gitea web interface (default port 3000). The module interacts with several Gitea API endpoints to perform version checks, create and migrate repositories, and trigger the vulnerability. The structure is typical for a Metasploit exploit: it defines targets, payloads, options, and the main exploit logic, and it uses Metasploit's HTTP client/server mixins to interact with the target and serve payloads as needed.
This repository provides a proof-of-concept exploit for CVE-2022-30781, a remote command execution vulnerability in Gitea's repository migration feature. The exploit works by serving a crafted set of files (mimicking a repository API) via HTTP. The attacker instructs the target Gitea instance to migrate a repository from the attacker's HTTP server (e.g., http://<your_host>/e99/exp). The crafted migration data includes a malicious payload in the 'ref' field of a pull request, such as '--upload-pack=bash -c 'whoami > /tmp/pwned'', which is executed on the Gitea server. The repository contains mostly JSON and HTML files representing API responses, with the main payload and command customization located in 'api/v1/repos/e99/exp/pulls/index.html'. The README provides clear usage instructions and references. The exploit is not weaponized but is a functional POC that demonstrates arbitrary command execution on vulnerable Gitea instances.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.