CVE-2026-58424 is a high-severity authorization flaw in Gitea Actions affecting fork-based pull request workflow approval handling. After a maintainer approves a workflow run from a contributor's forked pull request once, the platform can incorrectly persist trust for that contributor, allowing subsequent workflow runs from later fork pull requests to execute without undergoing the intended approval gate again. The weakness is fundamentally an authorization and permission enforcement failure in the pull request workflow approval model, consistent with improper or incorrect authorization. Because fork pull request workflows may execute attacker-controlled automation in the CI environment, the flaw can be used to bypass repository protections intended to prevent untrusted fork code from running automatically.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single Python exploit script and a README. The Python file is a full proof-of-concept/operational exploit for CVE-2026-58424, a Gitea Actions approval-gate bypass affecting Gitea <= 1.26.2. The exploit targets fork-based pull request workflows by injecting a malicious workflow into an attacker-controlled fork, widening the workflow trigger set to include unguarded events such as pull_request_review, then opening a PR and posting a review to cause immediate workflow execution without maintainer approval. The exploit’s main capabilities are: authenticating to Gitea via token, Kerberos/SPNEGO, or cookie; creating or reusing a fork; enabling Actions on the fork; injecting a malicious workflow file; optionally detecting runner labels; disabling inherited workflows to reduce interference; opening a PR against the target repository; triggering the bypass through the PR review API; and optionally cleaning up artifacts afterward. The intended outcome is remote code execution on the act_runner host as the runner service account, usually via a reverse shell callback to the attacker. Repository structure is minimal and focused: CVE-2026-58424.py is the primary entry point and contains the exploit logic, CLI handling, payload generation, workflow injection, trigger sequence, and cleanup flow. README.md documents the vulnerability, prerequisites, usage, attack flow, detection ideas, and remediation. This is not a framework module and not merely a detector; it is a working exploit with configurable payload delivery and target interaction over Gitea’s web/API surface.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.