Patch released Gitea web-app info-disclosure
Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
CVE Tools coverage
Unauthenticated attackers could read arbitrary files accessible by the Gitea service account in versions 1.22.1 through 1.27.0 of the self-hosted Git platform. This vulnerability, tracked as CVE-2026-59774, allows access using a public repository and maliciously crafted Org-mode markup without requiring login or write permissions. The flaw has been resolved in Gitea version 1.27.1.
The vulnerability poses a high risk due to its critical CVSS score of 9.8 and potential escalation to remote code execution under certain conditions. Gitea recommends immediate upgrades for self-hosted users, while cloud instances will be updated automatically during scheduled maintenance.