A critical authorization flaw in Gitea let tokens meant for public repositories indirectly write into private ones and trigger automation there.
A critical authorization bug in Gitea raises a familiar but dangerous question: what happens when a token that should stay on the public side of the fence can still touch private branches and CI workflows?