Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
Overview
A serious vulnerability has been discovered in Gitea, the self-hosted Git service, that allows unauthenticated attackers to read any file that the service account can access. This flaw affects versions 1.22.1 through 1.27.0, requiring only a public repository and some specially crafted Org-mode markup to exploit. The vulnerability, tracked as CVE-2026-59774, has been rated Critical with a CVSS score of 9.8, indicating a severe risk. Users of affected Gitea versions should update to version 1.27.1 or later to secure their systems against this issue, as the flaw poses a significant risk of data exposure without needing any login credentials.
Key Takeaways
- Affected Systems: Gitea versions 1.22.1 through 1.27.0
- Action Required: Update to Gitea version 1.
- Timeline: Disclosed on October 2023
Original Article Summary
An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Org-mode markup are enough. The flaw is fixed in Gitea 1.27.1. The file-read flaw is tracked as CVE-2026-59774, rated Critical with a CVSS score of 9.8, and received its
Impact
Gitea versions 1.22.1 through 1.27.0
Exploitation Status
No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.
Timeline
Disclosed on October 2023
Remediation
Update to Gitea version 1.27.1 or later to mitigate the vulnerability.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Exploit, Vulnerability, and 2 more.