CVE-2026-103667: Gitea container registry stored XSS through blob media type
Gitea's container registry served blob downloads with a Content-Type taken from the media type declared in pushed image manifests, without a Content-Disposition or restrictive content security policy. A user who can push container images can publish a blob containing HTML and JavaScript with a text/html media type. When a victim who is authenticated to the instance opens the blob URL in a browser, the script runs on the Gitea origin and can perform actions as the victim, such as creating API tokens.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs permission to push container images to the Gitea container registry. They can then publish a blob declared as text/html that contains malicious HTML and JavaScript.
What must happen for the attack to succeed?
An authenticated user must open the attacker-controlled blob URL in a browser. The supplied script then executes on the Gitea origin with the victim's authenticated session context.
What could an attacker do through a successful exploit?
The script can perform actions as the victim on the Gitea instance. The advisory specifically notes that it can create API tokens.
Are users who only pull images exposed?
Users are exposed when they open a malicious blob URL in a browser while authenticated to the affected Gitea instance. The provided information does not state that merely pulling an image triggers the issue.