Source status: Gitea's affected-project advisory explicitly names Claude in the discovery collaboration and publishes the fixed versions for CVE-2026-58435.
Summary
The flaw allowed a Git LFS deploy-key authorization boundary to be crossed in ways not intended by the repository’s access model. Gitea accepted and fixed the report, and its advisory provides direct Claude-assisted attribution.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.