All findings

CVE-2026-58435 high

Gitea directly credits Claude-assisted research on LFS deploy-key escalation

Gitea's upstream advisory credits Doyensec's Claude-assisted research on an LFS deploy-key privilege escalation.

Bug class
Deploy-key privilege escalation in Git LFS access control
Affected codebase
Gitea Git LFS authorization
Credited system
Claude / Anthropic Research
Disclosed
August 13, 2026
Attribution
Direct source attribution
Severity
high
Source status: Gitea's affected-project advisory explicitly names Claude in the discovery collaboration and publishes the fixed versions for CVE-2026-58435.

Summary

The flaw allowed a Git LFS deploy-key authorization boundary to be crossed in ways not intended by the repository’s access model. Gitea accepted and fixed the report, and its advisory provides direct Claude-assisted attribution.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.