Skip to content

Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

Moderate
bircni published GHSA-prr9-9mp4-5gp2 Jul 13, 2026

Package

gomod gitea.dev (Go)

Affected versions

<= 1.26.4

Patched versions

1.27.0

Description

Summary

PR #38145 fixed ListPublicMembers and IsPublicMember but missed
ListMembers. Any authenticated user can enumerate ALL members
(not just public ones) of a private organization.

Affected Versions

<= v1.26.4 (latest) and main branch

Root Cause

routers/api/v1/org/member.go — ListMembers():

// Missing check:
if !organization.HasOrgOrUserVisible(ctx,
ctx.Org.Organization.AsUser(), ctx.Doer) {
ctx.APIErrorNotFound()
return
}

Proof of Concept

Setup: privateorg (private), alice = member, bob = outsider

Bob lists ALL members of private org

curl -s "http://gitea/api/v1/orgs/privateorg/members"
-H "Authorization: token BOB_TOKEN"

Result: HTTP 200

[{"login":"alice","email":"alice@test.com",...}]

Expected: HTTP 404

Note

This is an incomplete fix variant of PR #38145.
That PR fixed public_members endpoints only.
ListMembers (/orgs/{org}/members) remains unpatched.

Fix

Add to ListMembers():
if !organization.HasOrgOrUserVisible(ctx,
ctx.Org.Organization.AsUser(), ctx.Doer) {
ctx.APIErrorNotFound()
return
}

Severity

Moderate

CVE ID

CVE-2026-58427

Weaknesses

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. Learn more on MITRE.

Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. Learn more on MITRE.

Credits