Dossier
CVE-2026-59774
Coverage of CVE-2026-59774 in the Nexus archive.
- Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
An unauthenticated attacker could exploit a critical flaw in Gitea versions 1.22.1 through 1.27.0 to read any file accessible by the service account. The vulnerability, tracked as CVE-2026-59774, requires only a public repository and crafted Org-mode markup. The issue was fixed in Gitea 1.27.1.