AI analysis
Gitea's container registry serves blob downloads with a Content-Type taken from the media type in a pushed image manifest, and it does not set Content-Disposition or a restrictive content security policy. A user who can push container images can store a blob of HTML and JavaScript declared as text/html. If an authenticated victim opens that blob URL in a browser, the script runs on the Gitea origin and can act as the victim, including creating API tokens. This is stored cross-site scripting (CWE-79), scored CVSS 3.1 5.4 (medium), and it requires both push access and a victim click. It is not in CISA KEV, and no public proof-of-concept is known.
What to do: Apply the vendor fix for CVE-2026-103667 as soon as a patched Gitea release is published; this record does not name a fixed version. Until then, limit container-registry push rights to trusted users, avoid opening blob URLs from untrusted images while authenticated, and review API tokens and audit logs for unexpected token creation.
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Gitea's container registry served blob downloads with a `Content-Type` taken from the media type declared in pushed image manifests, without a `Content-Disposition` or restrictive content security policy. A user who can push container images can publish a blob containing HTML and JavaScript with a `text/html` media type. When a victim who is authenticated to the instance opens the blob URL in a browser, the script runs on the Gitea origin and can perform actions as the victim, such as creating API tokens.