CyberSecurity News
Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
AI summary
A critical vulnerability in Gitea, a self-hosted Git platform, allows unauthenticated attackers to read server files. This can be done by creating a public repository and using specially crafted Org-mode markup, without needing login or write access. The issue affects Gitea versions 1.22.1 through 1.27.0. The flaw has been fixed in version 1.27.1. The vulnerability is tracked as CVE-2026-59774 and has a CVSS score of 9.8, indicating a high level of severity.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

