CVE Tools

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup

The Hacker NewsBy The Hacker News

PatchGitea

Our summary

Unauthenticated attackers could read arbitrary files accessible by the Gitea service account in versions 1.22.1 through 1.27.0 of the self-hosted Git platform. This vulnerability, tracked as CVE-2026-59774, allows access using a public repository and maliciously crafted Org-mode markup without requiring login or write permissions. The flaw has been resolved in Gitea version 1.27.1.

The vulnerability poses a high risk due to its critical CVSS score of 9.8 and potential escalation to remote code execution under certain conditions. Gitea recommends immediate upgrades for self-hosted users, while cloud instances will be updated automatically during scheduled maintenance.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store