Cyber Resilience
← All news
Corroborated

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup

Our takeGitea fixed CVE-2026-59774 (CVSS 9.8) that let unauthenticated attackers read any file the service account could reach via crafted Org-mode markup in a public repo. It affected 1.22.1–1.27.0; update to 1.27.1 if you self-host.
Sources (4)
What this means for you — Security leader:Update Gitea to 1.27.1 or later immediately if you self-host; the unauthenticated file-read flaw (CVE-2026-59774, CVSS 9.8) can be triggered with a public repo and crafted Org-mode markup.
What this means for you — Lean IT orgs:If you run your own Gitea server, update it to version 1.27.1 right away. An attacker can read any file on the server without a login.
What this means for you — MSP:Audit all client Gitea instances for versions 1.22.1–1.27.0 and push the 1.27.1 upgrade; the unauthenticated file-read vulnerability (CVE-2026-59774) requires only a public repository.
What this means for you — Researcher:Gitea 1.22.1–1.27.0 allows unauthenticated file reads via crafted Org-mode markup in a public repo (CVE-2026-59774, CVSS 9.8). Fixed in 1.27.1.