CVE Tools
Back to feed
Patch released Gitea web-app info-disclosure

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup

The Hacker News·By The Hacker News··3 min read
CVE Tools coverage

Unauthenticated attackers could read arbitrary files accessible by the Gitea service account in versions 1.22.1 through 1.27.0 of the self-hosted Git platform. This vulnerability, tracked as CVE-2026-59774, allows access using a public repository and maliciously crafted Org-mode markup without requiring login or write permissions. The flaw has been resolved in Gitea version 1.27.1.

The vulnerability poses a high risk due to its critical CVSS score of 9.8 and potential escalation to remote code execution under certain conditions. Gitea recommends immediate upgrades for self-hosted users, while cloud instances will be updated automatically during scheduled maintenance.