maksit-gitea-cursor/SECURITY.md
2026-08-26 21:07:02 +02:00

1.4 KiB

Security policy

This plugin talks to your Gitea instance with your personal access token. Treat the token like a password.

Report a vulnerability

Email security-reports@cursor.com if the issue is in how Cursor loads plugins.

For this repository, open a private security advisory on MAKS-IT-COM/maksit-gitea-cursor, or email maksym.sadovnychyy@gmail.com. Do not file a public issue that includes tokens, secrets, or a working exploit.

What this plugin does

  • Sends Authorization: token … only to {GITEA_URL}/api/v1/....
  • Rejects absolute URLs, .. path segments, and redirects that leave that API prefix.
  • Requires HTTPS except for localhost (override with GITEA_ALLOW_HTTP=true on a trusted network only).
  • Defaults to a curated toolset. Admin APIs, raw gitea_request, Actions secrets, runner tokens, and PAT create/delete are off until you set the matching env flag.

What you should do

  • Create a Gitea token with the minimum scopes you need. Do not grant site-admin unless you also set GITEA_ENABLE_ADMIN=true and understand the risk.
  • Prefer GITEA_READ_ONLY=true for review-only agents.
  • Never commit .env files or paste tokens into issues, skills, or chat logs.
  • Trust self-signed certificates in the OS trust store. This plugin does not disable TLS verification.