Skip to content
The Nexus
SECURITYAug 5 · 11:04 UTCTHE HACKER NEWS[email protected] (The Hacker News)

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup

An unauthenticated attacker could exploit a critical flaw in Gitea versions 1.22.1 through 1.27.0 to read any file accessible by the service account. The vulnerability, tracked as CVE-2026-59774, requires only a public repository and crafted Org-mode markup. The issue was fixed in Gitea 1.27.1.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
Related Signal

Adjacent reporting